
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1793 is an arbitrary file read vulnerability in the Element Pack Addons for Elementor WordPress plugin, affecting all versions up to and including 8.3.17. The flaw resides in the SVG widget's render_svg function, which lacks sufficient file validation, enabling path traversal to read arbitrary server files. It was published on February 15, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The render_svg function in the plugin's SVG widget does not adequately validate or sanitize file paths supplied by users, allowing an attacker to supply a crafted path that traverses outside the intended directory. Exploitation requires network access and at least contributor-level authentication on the WordPress site; no user interaction is needed beyond the attacker's own authenticated session (Red Hat CVE, Wordfence).
Successful exploitation allows authenticated attackers with contributor-level access or above to read the contents of arbitrary files on the server, including sensitive configuration files such as wp-config.php (which may contain database credentials), /etc/passwd, private keys, or other secrets stored on the filesystem. This is a confidentiality-only impact — integrity and availability are not directly affected — but exposed credentials could enable further compromise, privilege escalation, or lateral movement within the hosting environment (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.048% (0.000480), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum contributor-level WordPress credentials, which limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE, Wordfence).
../../wp-config.php) to reference a target file outside the intended directory.render_svg: Save or preview the page/post containing the malicious widget, causing the server to invoke the render_svg function with the attacker-controlled path.wp-config.php), enabling further exploitation (Red Hat CVE).../, %2e%2e%2f).render_svg function outside the uploads or plugin directories.Site administrators should update the Element Pack Addons for Elementor plugin to a version beyond 8.3.17 that includes a fix for the render_svg file validation issue. Until a patch is applied, consider restricting contributor-level user registration or limiting access to the Elementor editor for untrusted users. Web application firewalls (WAFs) with rules targeting path traversal patterns can provide an additional layer of defense (Wordfence, Red Hat CVE).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as part of broader plugin security tracking (Wordfence). The vulnerability was also noted by INCIBE-CERT and CCN-CERT (Spanish national cybersecurity agencies) in their early warning bulletins. No significant independent researcher commentary or social media discussion beyond routine CVE aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."