Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services security advisory graphic: Elementor Pro critical RCE flaw CVE-2026-32475, update to 4.2.2 now

Critical Elementor Pro Flaw Lets Attackers Take Over WordPress Sites

If your business website runs on WordPress, this one’s worth five minutes today. Researchers have disclosed a critical flaw in Elementor Pro — the paid version of the page builder used on 10 million-plus sites — that lets an attacker upload a file and run their own code on your server. Tracked as CVE-2026-32475, it affects every version before 4.2.2. BleepingComputer reported it on 20 August, based on a write-up from WordPress security firm Patchstack.

The nuance matters. You’re only exposed if a published Elementor form has a file-upload field with the “multiple files” option switched on — and that’s off by default, so most sites are fine. But plenty of Australian small businesses have exactly that: a Northern Beaches café taking catering enquiries, or a Central West trades firm collecting job photos, often on a form a web designer built years ago and nobody has touched since. No login is needed. From there, an attacker can deface the site, steal data submitted through your forms, or serve malware to your visitors.

Update Elementor Pro to 4.2.2 or later today. Then check the wp-content/uploads/elementor/forms/ folder for stray PHP files — Patchstack warns that patching does not remove anything an attacker already uploaded, so a clean update is not proof of a clean site. No exploitation has been seen in the wild yet, but enough detail is public that it won’t stay that way.

Here’s the honest bit: we run Elementor on our own site, so this hit our list this morning too — and our first move was to check that uploads folder, not just click “update.” It’s a pattern we keep seeing: the website is the one system nobody actively manages, because no one logs into it every day. If you’re not sure who patches your site, our cybersecurity team can take a look.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →