Critical Elementor Pro Flaw Lets Attackers Take Over WordPress Sites
If your business website runs on WordPress, this one’s worth five minutes today. Researchers have disclosed a critical flaw in Elementor Pro — the paid version of the page builder used on 10 million-plus sites — that lets an attacker upload a file and run their own code on your server. Tracked as CVE-2026-32475, it affects every version before 4.2.2. BleepingComputer reported it on 20 August, based on a write-up from WordPress security firm Patchstack.
The nuance matters. You’re only exposed if a published Elementor form has a file-upload field with the “multiple files” option switched on — and that’s off by default, so most sites are fine. But plenty of Australian small businesses have exactly that: a Northern Beaches café taking catering enquiries, or a Central West trades firm collecting job photos, often on a form a web designer built years ago and nobody has touched since. No login is needed. From there, an attacker can deface the site, steal data submitted through your forms, or serve malware to your visitors.
Update Elementor Pro to 4.2.2 or later today. Then check the wp-content/uploads/elementor/forms/ folder for stray PHP files — Patchstack warns that patching does not remove anything an attacker already uploaded, so a clean update is not proof of a clean site. No exploitation has been seen in the wild yet, but enough detail is public that it won’t stay that way.
Here’s the honest bit: we run Elementor on our own site, so this hit our list this morning too — and our first move was to check that uploads folder, not just click “update.” It’s a pattern we keep seeing: the website is the one system nobody actively manages, because no one logs into it every day. If you’re not sure who patches your site, our cybersecurity team can take a look.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
