Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.
A critical arbitrary file upload bug in Forminator Forms, running on more than 600,000 WordPress sites, lets unauthenticated attackers execute…