Vendor
high
advisory
Unauthenticated Remote Code Execution in Elementor Pro
1 rule 2 TTPs 2 CVEsElementor Pro versions 4.2.1 and below contain a critical file upload vulnerability (CVE-2026-32475) that allows unauthenticated attackers to achieve remote code execution by bypassing extension validation.
Elementor Pro +1
web-vulnerability
wordpress
remote-code-execution
cve-2026-32475
1r
2t
2c
high
advisory
WordPress Hide My WP Lite Plugin Vulnerable to Arbitrary File Read (CVE-2026-13347)
1 rule 2 TTPs 1 CVEThe Hide My WP Lite plugin for WordPress, versions up to and including 1.3, is vulnerable to Arbitrary File Read (CVE-2026-13347) due to inadequate validation of user-supplied input in query parameters `he_wrapper_js` and `he_wrapper_css` within the `elementor_assets_filter()` function, allowing unauthenticated attackers to read arbitrary files on the server like `wp-config.php` when the Elementor plugin and 'Hide Elementor' feature are enabled.
Hide My WP Lite <= 1.3 +1
wordpress
plugin
arbitrary-file-read
path-traversal
web-application
cve
1r
2t
1c