CVE-2026-28192 CRITICAL

CVE-2026-28192: WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability

Vendor Piotnet
Product Piotnet Addons For Elementor Pro
Weakness CWE-434 · Unrestricted file upload
Published August 18, 2026
Last update August 18, 2026

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Piotnet Addons For Elementor Pro versions up to 7.1.67 allow unauthenticated users to upload files of dangerous types. An attacker can trick a site visitor into uploading a malicious file (such as a PHP script) by visiting a crafted link. This grants the attacker the ability to run their own code on the site, read sensitive data, and disrupt service.

What an attacker can do

03Attacker Capabilities

Upload and execute malicious files on the site, run arbitrary code, steal data, or take the site offline.

Potential impact on your site

04Site Impact

Attackers can gain full control of your site, steal customer data, inject malware, or render it unavailable.

Conditions required to exploit

05Prerequisites

No authentication required. The victim must click a link or visit a page controlled by the attacker.

Key dates

06Disclosure timeline

August 18, 2026 CVE published

Related vulnerabilities

08Related CVE