Multiple WordPress Plugins Vulnerable to Unauthenticated RCE via PHP Uploads

Multiple WordPress Plugins Vulnerable to Unauthenticated RCE via PHP Uploads

First seen 20 Aug 2026, 07:53 UTC Thehackernews 75% similarity 67.5

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in popular WordPress plugins, Elementor Pro and Forminator, allowing unauthenticated attackers to upload malicious PHP files and execute code. The Elementor Pro flaw, reported on August 20, 2026, poses a significant risk as it enables remote code execution (RCE) without authentication. Similarly, the Forminator vulnerability, disclosed on August 17, 2026, allows for the same type of attack. Both plugins are widely used, increasing the potential impact on numerous WordPress sites. The vulnerabilities have not been assigned CVEs yet, but they are critical for site administrators to address. Users are urged to monitor their installations and apply patches as soon as they become available. The situation is evolving, and security teams should prioritize these vulnerabilities to mitigate risks.

Key Points: • Elementor Pro and Forminator plugins have critical RCE vulnerabilities allowing PHP uploads. • Both vulnerabilities enable unauthenticated access, increasing the risk for WordPress sites. • Site administrators should monitor for patches and apply them immediately to secure their environments.

ThreatCluster AI How this analysis works

Timeline

2026-08-17
Forminator vulnerability disclosed
A flaw in the Forminator plugin allows unauthenticated RCE via malicious PHP uploads, affecting numerous WordPress sites.
Thehackernews
2026-08-20
Elementor Pro vulnerability disclosed
A critical flaw in Elementor Pro enables unauthenticated attackers to upload PHP files and execute code.
Thehackernews

Community

Browse all →

Tracked Entities in This Story