Critical Elementor Pro bug exposes WordPress sites to RCE attacks
…The researchers say that after uploading the malicious PHP, an attacker can determine its filename in the public directory because it is created using the uniqid() function, which is not random but…