CyberHighSingle-sourceAccelerating
7.4
MikroTik Patches Critical Flaws Chained to Hack Routers
SecurityWeek·1 day ago
A critical arbitrary file upload vulnerability (CVE-2026-32475, CVSS 9.8) in the Elementor Pro WordPress plugin is being actively exploited to compromise websites. The flaw resides in the form submission handler, allowing unauthenticated attackers to upload malicious files, likely leading to remote code execution. This poses a significant risk to the large installed base of Elementor Pro users, potentially enabling mass website takeovers and supply-chain attacks.