Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

2026-08-20T07:24:00Zfe4f53a00b93cd871c25073cccdaf7f296bb241b87fbed765979acc1903050bc
CVE-2026-15748CVE-2026-19478CVE-2026-32475CVE-2026-65400active-exploitationai-securitycisa-kevcloud-securitycredential-theftdahuaelementor-proespionageforminatorgitlabinformation-stealeriotmalwaremlflowphishingransomwarerayremote-code-executionsharepointsupply-chainvmwarevulnerabilitiesweb-shellwordpress

What happened

The feed reports multiple critical vulnerabilities and active exploitation campaigns, including unauthenticated remote code execution in Elementor Pro and Forminator WordPress plugins, actively exploited flaws in Ray and other enterprise platforms, GitLab project deletion, MLflow SSRF credential theft, and compromises of Dahua devices. It also covers malware and espionage campaigns targeting governments, macOS users, RubyGems developers, WordPress sites, Microsoft cloud services, and AI-agent ecosystems. Overall, the reporting indicates significant risk across internet-facing applications, IoT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
fe4f53a00b93cd871c25073cccdaf7f296bb241b87fbed765979acc1903050bc
Enrichment time
2026-08-20T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code · Baitaphish