Impact
An unauthenticated arbitrary file upload flaw exists in Piotnet Addons For Elementor Pro versions 7.1.67 and earlier. This weakness, classified as CWE-434, allows an attacker to upload any file type without restrictions or authentication, potentially leading to the placement of executable code on the server. Once an attacker has uploaded a malicious script, they can execute it, compromise the site, and possibly gain full control of the underlying web server.
Affected Systems
WordPress sites that have installed the Piotnet Addons For Elementor Pro plugin version 7.1.67 or any earlier release from the Piotnet vendor are affected. The vulnerability does not apply to later, patched releases.
Risk and Exploitability
The CVSS score of 9.6 indicates a high likelihood of successful exploitation and a significant impact on confidentiality, integrity, and availability. While an EPSS score is not available, the high CVSS combined with the lack of authentication processing suggests that attackers can target the vulnerable upload endpoint through the public web interface and achieve remote code execution. The vulnerability is not listed in the CISA KEV catalog, but its severity and exploitation potential warrant immediate attention.
OpenCVE Enrichment