Thehackernews
Multiple WordPress Plugins Vulnerable to Unauthenticated RCE via PHP Uploads
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two vulnerabilities have been identified in popular WordPress plugins, Elementor Pro and Forminator, allowing unauthenticated attackers to upload malicious PHP files and execute code. The Elementor Pro flaw, reported on August 20, 2026, poses a significant risk as it enables remote code execution (RCE) without authentication. Similarly, the Forminator vulnerability, disclosed on August 17, 2026, allows for the same type of attack. Both plugins are widely used, increasing the potential impact on numerous WordPress sites. The vulnerabilities have not been assigned CVEs yet, but they are critical for site administrators to address. Users are urged to monitor their installations and apply patches as soon as they become available. The situation is evolving, and security teams should prioritize these vulnerabilities to mitigate risks.
Key Points: • Elementor Pro and Forminator plugins have critical RCE vulnerabilities allowing PHP uploads. • Both vulnerabilities enable unauthenticated access, increasing the risk for WordPress sites. • Site administrators should monitor for patches and apply them immediately to secure their environments.