CVE-2026-28192
Received Received - Intake

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro

Vulnerability report for CVE-2026-28192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Patchstack

Description

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
piotnet addons_for_elementor_pro to 7.1.67 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-28192 is an Unauthenticated Arbitrary File Upload vulnerability affecting Piotnet Addons For Elementor Pro plugin versions 7.1.67 and below. It allows attackers to upload malicious files, such as backdoors, to a website without authentication. Exploitation requires a privileged user to perform an action like clicking a link or submitting a form.

Detection Guidance

Check if the Piotnet Addons For Elementor Pro plugin version 7.1.67 or below is installed on your WordPress site. Look for unauthorized file uploads in directories like /wp-content/uploads/ or /wp-content/plugins/. Use security plugins to scan for suspicious activity or file changes.

Impact Analysis

This vulnerability can lead to unauthorized access to your website, allowing attackers to upload malicious files. These files could be used to gain control over your site, steal data, or use it for further attacks. Even though exploitation requires user interaction, the risk is high due to the potential impact on website integrity and security.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR and HIPAA compliance requirements. Unauthorized file uploads might expose sensitive user data, resulting in legal penalties, reputational damage, and loss of trust. Immediate mitigation is advised to prevent compliance violations.

Mitigation Strategies

Disable the Piotnet Addons For Elementor Pro plugin immediately if installed. Apply Patchstack's mitigation rule if available. Update the plugin to the latest version once an official patch is released. Consider seeking help from a hosting provider or web developer for further protection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart