⚠️ Security update: WordPress Elementor plugin <= 3.18.0 - Arbitrary File Upload vulnerability
Hi guys, this blog update concerns a newly discovered vulnerability affecting the Elementor plugin up to version 3.18.0. The vulnerability Hồng Quân (luk6785 at VNPT-VCI) discovered and reported this Arbitrary File Upload vulnerability in WordPress Elementor Website Builder Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has not been known to be fixed yet. Now, before you freak out and reset your website, I've got some reassuring details for you: This vulnerability can be exploited by users with at least Contributor privileges. This means that if you don't have any additional user, or the user is a simple subscriber or commenter, your site has nothing to fear It seems this vulnerability is only exploitable if […]