AntiMalwareAugust 21, 2026🇷🇺Translated from Russian

Critical Unauthenticated File Upload Flaw in Elementor Pro Allows Remote Code Execution on WordPress Sites

A critical vulnerability identified as CVE-2026-32475 has been found in the Elementor Pro plugin for WordPress, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on affected sites.

The issue affects all versions prior to 4.2.2 and stems from inconsistent handling of empty filenames between the validation and file-saving routines in the upload module. Researchers at Patchstack determined that an attacker can craft a multipart request where the first part contains a file with no name and the second part delivers a PHP backdoor.

Because the validation loop fails on the empty entry and aborts early, the malicious payload reaches the upload handler, which saves it to the publicly writable directory wp-content/uploads/elementor/forms/. The attacker can then guess the filename based on creation timestamps or obtain the exact path through autoresponder emails in certain configurations.

Successful exploitation requires a published Elementor Pro form that includes a file-upload field with the multiple-file attachment option enabled; this setting is disabled by default. The free version of Elementor, which has more than 10 million installations, is not impacted.

Developers addressed the flaw in Elementor Pro 4.2.2. Site owners should apply the update without delay and inspect the upload directory for unexpected PHP files or other anomalies. The patch does not remove any previously planted backdoors. No active attacks have been recorded so far, but publication of technical details is expected to prompt exploitation attempts.

Related articles

Security NEXTVulnerabilities & Exploits

CISA Adds Two Remotely Exploitable TrueConf Server Vulnerabilities to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency has added two critical vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog. CVE-2026-72529 allows unauthenticated remote attackers to execute arbitrary scripts due to missing authentication in a critical function. CVE-2026-72530 is a code injection flaw that enables attackers to run arbitrary code on the underlying host system by escaping the sandboxed environment. Both issues can be exploited over TCP port 4307 without requiring authentication. Kaspersky assigned CVSS v3.1 base scores of 9.8 and 9.0 respectively, rating both as Critical. US federal agencies must apply mitigations for the first vulnerability by August 23 and for the second by September 3.

AntiMalwareVulnerabilities & Exploits

Zombie Card Attack Revives Expired Visa Cards for Contactless NFC Payments

Researchers from the University of Massachusetts Amherst have demonstrated the Zombie Card attack, which enables contactless payments with certain expired Visa cards over NFC without breaking cryptography or cloning the card. The technique exploits inconsistencies in how payment terminals and issuing banks validate card expiration dates within the EMV protocol. By deploying two Android smartphones as a relay between the expired card and the terminal, the researchers intercepted the EMV field containing the expiration date and substituted a future date during the transaction. The terminal accepted the locally validated payment while the cryptographic data remained valid because Visa EMV Kernel 3 does not always bind the expiration field to the protected cryptogram. Testing showed varying bank responses: one issuer approved transactions of different amounts at multiple merchants, while another consistently declined them. The attack failed against Mastercard, American Express, and Discover due to stricter cross-checks or cryptographic protection of the expiration data. The method requires an active account and valid keys on the expired card, making it more complex than traditional skimming.

HabrVulnerabilities & Exploits

Claude Discovers Vulnerabilities Across 16 SAML Projects in One Month, Exposing Maintenance Gaps

Security researcher Eric Chiang used Anthropic's Claude Opus model to identify vulnerabilities in 16 SAML implementations over roughly one month of evening work. The effort uncovered four full authentication bypasses in projects including Authentik, lightsaml, OneUptime, and saml-client, plus twelve additional signature bypass issues affecting secondary protocol messages. A notable finding was CVE-2026-57580 in Authentik, independently reported by eight researchers, which allowed XML comment injection in the NameID field to hijack accounts under specific configuration settings. Chiang built a two-phase agent pipeline that first searched for behavioral anomalies in libraries and then combined them into working exploits, without needing to train the model on prior SAML vulnerabilities. Many maintainers either ignored reports or struggled to distinguish real issues from AI-generated noise, with one project requiring three iterations of fixes before the patches held. The researcher concluded that while discovering SAML flaws has become inexpensive, patching them remains costly and under-resourced, reinforcing his long-standing recommendation to avoid custom SAML code in favor of established libraries or OpenID Connect.

HabrVulnerabilities & Exploits

Mind Games: 30 Years of Hacking and Securing Game Consoles

The article traces the evolution of security mechanisms in home game consoles from the unprotected Atari 2600 in 1977 through hardware locks, optical media protections, and cryptographic boot chains up to the seventh generation. Early systems like the NES relied on the 10NES/CIC chip for mutual authentication using identical Sharp SM590 microcontrollers, which was quickly defeated by Tengen's Rabbit clone and physical pin-clipping attacks. PlayStation introduced SCEx regional signals on discs, leading to widespread modchip installations and swap tricks that bypassed all code verification. Microsoft’s original Xbox implemented a full cryptographic chain of trust starting from the MCPX southbridge, yet it fell to HyperTransport bus sniffing by bunnie Huang and buffer overflows in titles such as MechAssault. Nintendo Wii’s Twilight Hack exploited a stack overflow via an excessively long horse name in The Legend of Zelda: Twilight Princess, enabling unsigned code execution. The piece highlights recurring lessons about the limits of security-through-obscurity and the necessity of protecting both boot chains and runtime memory handling.