WordPress Plugin Vulnerabilities

Elementor Pro < 4.2.2 - Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass

Description

The Elementor Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 4.2.1 via the process_field function. This is due to a validation loop in Upload::validation() using 'return' instead of 'continue' when the first array element has UPLOAD_ERR_NO_FILE, aborting all extension and file type checks for remaining files in the same upload field. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.

Affects Plugins

Fixed in 4.2.2

References

Miscellaneous

Original Researcher
Tin Pham (TF1T), Austin Ginder
Verified
No

Timeline

Publicly Published
2026-08-19 (about 1 month ago)
Added
2026-08-19 (about 1 month ago)
Last Updated
2026-10-07 (about 7 minutes ago)

Other