Executive brief
The Piotnet Addons for Elementor Pro plugin, a popular tool for building advanced forms and layouts in WordPress, contains a critical security flaw in its form builder component. This vulnerability allows an unauthenticated person to upload malicious files to the website's server if a file upload field is present on any form. An attacker could use this to take complete control of the website, potentially leading to data theft, site defacement, or a total service outage.
Technical details
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to an unrestricted file upload vulnerability within the 'pafe_ajax_form_builder' function. The root cause is an incomplete extension blacklist that filters common PHP extensions (php, phpt, php5, php7) and executables (exe) but fails to block dangerous alternatives like .phar or .phtml. An unauthenticated attacker can exploit this by submitting a form that includes a file upload field, uploading a malicious script, and then accessing it to achieve remote code execution (RCE). The vulnerability affects all versions up to and including 7.1.70.
Affected products
- Piotnet Piotnet Addons for Elementor Pro Up to, and including, 7.1.70
Timeline
- 2026-05-19: disclosed: CVE published to NVD
- 2026-05-19: advisory: Wordfence advisory published