Best WordPress Hosting
 

PSA: High Severity File Upload Vulnerability in Elementor Patched

via wordfence.com => original post link

On December 6, 2023, the Wordfence team noticed a changelog entry for version 3.18.1 of Elementor, a WordPress plugin installed on nearly 9 million sites. We did not discover the original vulnerability and only became aware of it after reviewing the changelog containing a partial patch. We immediately released a firewall rule to Wordfence Premium, Wordfence Care, and Wordfence Response customers. The firewall rule will be made available to free Wordfence users 30 days later, on January 5, 2023.

After reviewing the vulnerability further, we determined that the patch was insufficient and could still be exploited, though it would be more difficult.

We immediately contacted the Elementor team the same day, on December 6, 2023, to let them know that the patch failed to fully resolve the issue. Elementor released a sufficient patch in version 3.18.2 on December 8, 2023. We commend the team at Elementor in their swift response to this situation.