CVE-2026-4885Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 205-19
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4885 — CVSS 9.8/10 ██████████ The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/fchSZJ2bHh

    Post summary

    CVE-2026-4885 is a critical arbitrary file upload flaw in Piotnet Addons for Elementor Pro, with a CVSS score of 9.8, and vendors are urged to apply a patch.

    10000126
    42 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4885 The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' fun… https://www.cve.org/CVERecord?id=CVE-2026-4885

    Post summary

    The Piotnet Addons for Elementor Pro plugin for WordPress has been disclosed as vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function.

    00000146
    57.5K followersView on X

Explore more