WordPress Plugin Vulnerabilities
Elementor Pro < 4.2.2 - Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass
Description
The Elementor Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 4.2.1 via the process_field function. This is due to a validation loop in Upload::validation() using 'return' instead of 'continue' when the first array element has UPLOAD_ERR_NO_FILE, aborting all extension and file type checks for remaining files in the same upload field. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.
Affects Plugins
References
Miscellaneous
Original Researcher
Tin Pham (TF1T), Austin Ginder
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-08-19 (about 1 month ago)
Added
2026-08-19 (about 1 month ago)
Last Updated
2026-10-07 (about 7 minutes ago)