CVE-2026-4885 is a critical arbitrary file upload vulnerability in Piotnet Addons for Elementor Pro for WordPress affecting all versions through 7.1.70. The flaw is in the plugin's pafe_ajax_form_builder function, which handles file uploads for plugin-created forms. Instead of enforcing a strict allowlist of safe file types, the function relies on an incomplete extension blacklist that blocks only a small set of extensions while permitting other dangerous server-executable extensions such as .phar and .phtml. As a result, an unauthenticated attacker can submit a crafted upload through a vulnerable form containing a file upload field and place a malicious file on the server. In environments where those extensions are interpreted as PHP, the uploaded payload can then be invoked to achieve remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit repo with 2 files: a single Python exploit script (CVE-2026-4885.py) and a README describing usage and behavior. The script is a multithreaded mass-exploitation tool targeting unauthenticated arbitrary file upload in Piotnet Addons for Elementor Pro on WordPress, claimed for versions <= 7.1.70. The exploit workflow is operational rather than a simple proof of concept. It accepts a list of targets from a file, normalizes and scans each target, attempts to detect the vulnerable plugin version from homepage asset references or known plugin asset paths, then performs reconnaissance to locate Piotnet form pages and extract required parameters such as post_id, form_id, and the upload field name. The code uses regexes against Piotnet-specific HTML markers like data-pafe-form-builder-field-name and related upload/form attributes. Once reconnaissance succeeds, the script sends a crafted multipart request to the WordPress AJAX handler action pafe_ajax_form_builder, trying several PHP-capable extensions (.phtml, .php3, .php4, .phps, .pht, .php2) to bypass weak upload filtering. The embedded payload is a GIF89a-prefixed PHP web shell. After upload, the exploit queries the pafe_export_database AJAX action to leak the uploaded file URL, then requests that URL and checks for the marker string Logic_Internet to confirm code execution. Successful shell URLs are appended to shells.txt. Notable capabilities include mass targeting with up to 20 threads, automatic scheme handling, plugin/version detection, form discovery across common contact/application paths, upload-field extraction, upload attempts with multiple extensions, shell URL leakage, execution verification, and result persistence. The payload provides post-exploitation capability by exposing server information and a file-upload form, enabling further file transfer to the compromised host. Overall, this is a real exploit script, not merely a detector. It is not part of a larger framework and is designed specifically for unauthenticated web exploitation of vulnerable WordPress sites running the targeted Piotnet plugin.
This repository is a compact exploit package for CVE-2026-4885 affecting Piotnet Addons for Elementor Pro <= 7.1.70 on WordPress. It contains three files: a README describing the vulnerability and usage, a Python exploit script (shadow.py), and a PHP web shell payload (shadow.phtml). The exploit is not part of a major framework. The main capability is unauthenticated arbitrary file upload leading to remote code execution. The Python script supports both single-target and mass-target modes, uses asyncio/httpx for concurrent reconnaissance, and attempts to discover required Piotnet form parameters from public pages. Per the README and visible code, it identifies form_id, post_id, and file field names, uploads a GIF89a-prefixed PHP payload using a non-blocked extension such as .phtml, then leverages an unauthenticated export/leak mechanism to recover the final uploaded file URL. It also verifies successful execution and records working shell URLs to shell.txt. The included payload shadow.phtml is an active PHP web shell, not just a test file. It accepts uploaded files via form field f and executes arbitrary OS commands supplied through the cmd GET parameter using shell_exec. That makes the repository clearly an exploit with post-exploitation capability, not merely a detector. Fingerprintable targets and paths include the vulnerable AJAX actions pafe_ajax_form_builder and pafe_export_database, the WordPress uploads path /wp-content/uploads/piotnet-addons-for-elementor/, the local output file shell.txt, and the payload file shadow.phtml. Overall, the repository is purpose-built for operational exploitation of exposed vulnerable WordPress sites at scale.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.