CVE-2026-28192: WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Affected Software
1 affected component
WordPress Piotnet Addons For Elementor Pro<=7.1.67
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Sites running Piotnet Addons For Elementor Pro version 7.1.67 or earlier are affected according to the available data. The vulnerability is rated critical with a 9.6 CVSS score.
2
What access does an attacker need to exploit this?
An attacker does not need to authenticate, and the attack vector is network-accessible. The CVSS vector also indicates user interaction is required, but the provided data does not specify what user action is needed.
3
What is the potential impact of successful exploitation?
The issue allows arbitrary file upload and has high impact on confidentiality, integrity, and availability. The provided data does not identify a workaround or mitigation for systems that cannot be patched immediately.