What the vulnerability does
01Description
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Explanation of Vulnerability in Simple Terms
Piotnet Addons For Elementor Pro versions up to 7.1.67 allow unauthenticated users to upload files of dangerous types. An attacker can trick a site visitor into uploading a malicious file (such as a PHP script) by visiting a crafted link. This grants the attacker the ability to run their own code on the site, read sensitive data, and disrupt service.
What an attacker can do
Upload and execute malicious files on the site, run arbitrary code, steal data, or take the site offline.
Potential impact on your site
Attackers can gain full control of your site, steal customer data, inject malware, or render it unavailable.
Conditions required to exploit
No authentication required. The victim must click a link or visit a page controlled by the attacker.
Key dates
External resources
Related vulnerabilities