Wednesday, 09 July 2025

Critical flaw found in Elementor WordPress plugin

The developers of the Elementor Website Builder plugin for WordPress have released a new version 3.6.3 to address a critical remote code execution flaw that may impact as many as 500,000 websites. A threat actor creating a normal user account on an affected website could change the name and theme of the affected site making it look entirely different.

The vulnerability appeared in Elementor 3.6.0, released on March 22, 2022.

Source: securitylab.ru

15 April 2022

-
115