Impact
Xpro Elementor Addons exposes an unrestricted file upload vulnerability that allows an attacker to upload a web shell or other executable file to the web server. The flaw is a Classic Unrestricted Upload with Dangerous File Type, allowing attacker control over code execution on the host. As a result, an attacker could compromise the website, exfiltrate data, or use the host to launch further attacks. The weakness is identified as CWE-434.
Affected Systems
The vulnerability exists in the Xpro Elementor Addons plugin from all earlier releases up to version 1.4.19.1. Users running any of those versions are at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. The EPSS score of less than 1% suggests that exploitation is not widespread today, but the presence of this critical flaw means it could be targeted once it becomes widely known. The plugin is exposed through the WordPress admin upload interface, making the attack vector remote and straightforward for an authenticated or unauthenticated attacker with access to the upload form. The flaw is not listed in the CISA KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment