Unauthenticated File Upload Vulnerability in Piotnet Addons For Elementor Pro
CVE-2026-28192

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-28192?

The Piotnet Addons For Elementor Pro plugin is susceptible to an unauthenticated arbitrary file upload vulnerability. This allows malicious users to upload potentially harmful files to the server, which can compromise website security. Affected versions include those below 7.1.67. Mitigating this vulnerability requires updating to the patched version and implementing robust security measures to ensure server integrity.

Affected Version(s)

Piotnet Addons For Elementor Pro <= 7.1.67

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 | Patchstack Bug Bounty Program
.