WordPress Plugin Vulnerabilities
Elementor < 2.7.5 - Authenticated Arbitrary File Upload
Description
The Elementor plugin (version 2.7.4 and below) was found to be vulnerable to an arbitrary file upload. Due to the application not handling zip files with directories properly an attacker could upload php files which were executable, this allowed any user able to import templates (WordPress role "Contributor" or above) to execute commands on the underlying server.
Affects Plugins
References
Miscellaneous
Original Researcher
Sam Thomas and Kyle Fleming
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-01-14 (about 6 years ago)
Added
2020-05-13 (about 5 years ago)
Last Updated
2021-01-19 (about 5 years ago)