Skip to content
WordPress plugin Elementor Pro vulnerability: 6 million websites at risk

WordPress plugin Elementor Pro vulnerability: 6 million websites at risk

Heise.De August 21, 2026

The WordPress plugin Elementor Pro is used in over six million active installations, making it widely adopted. Consequently, a newly discovered vulnerability weighs heavily, as it allows unauthenticated attackers from the internet to upload arbitrary files, potentially leading to a complete takeover of a vulnerable WordPress instance.

This is currently being warned by the IT security company Wordfence . Specifically, the security vulnerability allows malicious actors from the internet to upload any files, including executable PHP files, to vulnerable instances without prior authentication. A prerequisite for exploiting the vulnerability is that a page with an Elementor Pro form widget containing at least one file upload field has been published; this field does not need to be marked as “required.” The trigger is therefore a logic error in the upload verification function (CVE-2026-32475, CVSS 9.8 , risk “ critical ”).

Wordfence was notified of the vulnerability through the company’s bug bounty program. The reporter receives a reward of $15,600 – an unusually high amount, indicating its practical severity for WordPress operators. IT security researchers informed the Elementor team the security leak at the end of July. The patched software version 4.2.2 has been available since Wednesday, August 19. Admins should check if their instances are already up to date and update them promptly if necessary.

Just at the beginning of the week, vulnerabilities in the popular WordPress plugins Forminator Forms and Royal Elementor Addons became known . There too, malicious code could be injected by uploading executable files without prior authentication, compromising entire instances. The plugins are each used in over 600,000 active installations.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.