Elementor Pro is vulnerable to Unrestricted File Upload
90
Critical Risk
The Forms File Upload field validates extensions and moves files using two loops that treat empty entries differently. An empty first file part makes validation() return before type-checking later entries and process_field() only skips that empty entry and still moves a following .php upload into the public forms directory. An unauthenticated visitor who submits a form with a File Upload field can therefore place executable PHP under wp-content/uploads/elementor/forms/ and achieve remote code execution. The fix aligns both loops on empty entries and re-checks the extension inside process_field() before moving the file.
You are affected if you are using a version that falls within the vulnerable range and publish an Elementor form that includes a File Upload field.
Elementor Pro is vulnerable to Unrestricted File Upload in versions 0.0.0 - 4.2.1.
Upgrade the Elementor Pro library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant