An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
https://pentest.co.uk/labs/vulnerability-disclosure-cve-2020-7055/