news.mlab.sh
4 results
vulnerability

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a discrepancy in how the plugin handles empty file entries in its File Upload field. While a patch (ver…

The Hacker News · Aug 20, 2026 High