Security

Elementor Pro had a critical vulnerability that let attackers take over your site without a password

CVE-2026-32475, rated 9.0 out of 10, affected Elementor Pro's file upload module. It's already patched, but it's worth understanding what happened and checking your installation.

Published on September 4, 2026 · The mitza.es team

Elementor Pro, the paid version of the most popular visual page builder for WordPress, had a critical vulnerability identified as CVE-2026-32475, rated 9.0 out of 10 on the CVSS scale. The flaw allowed an attacker to remotely execute code on the server without logging in or holding any kind of credential at all — finding the affected site was enough to exploit it directly.

What makes this vulnerability so serious

Elementor is, by a wide margin, one of the most widely used page builders in the WordPress ecosystem: the free plugin, the base on top of which the Pro version is installed, has more than 10 million active installs. That doesn't mean 10 million sites were running the affected Pro version, but it gives a sense of the scale of the ecosystem a flaw like this appears in: the more sites share the same piece of software, the more attractive it becomes for an attacker to automate the search for vulnerable installations.

The technical flaw, explained without jargon

The problem was in Elementor Pro's file upload module, the one used, for example, by forms that let a visitor attach a document. When someone uploaded a file with no filename, the validation code (the part that checks the file is of an allowed type) and the code that actually processed and saved the file didn't apply exactly the same logic: one of the two could exit its check early in that specific case. That small gap between "what gets validated" and "what gets processed" is exactly what an attacker needs: it allowed a disguised PHP file to be uploaded, bypassing the file-type filter, and once that malicious file sat on the server, running it directly. The result is remote control over the server, without ever logging in.

Which versions were affected

  • All versions of Elementor Pro before 4.2.2 were affected.
  • Version 4.2.2, already available, fixes the flaw.
  • The free version of Elementor (without "Pro") is not implicated in this specific CVE.

Timeline: a responsible disclosure, not a surprise attack

The encouraging part of this case is how it was handled. Researcher Tin Pham reported the flaw to Patchstack on July 16, 2026. The Elementor team had a fix ready the very next day, July 17. Patchstack verified the fix worked correctly on August 3, and the update finally reached users around August 19-20, 2026. As far as the available security reports show, no active exploitation of this flaw was detected before the patch — a case of responsible disclosure working the way it's supposed to.

That said, no mass exploitation to date doesn't mean the risk has disappeared. The technical details of the flaw are now public, and experience with other WordPress vulnerabilities — like the wp2shell chain in WordPress core we covered a few weeks ago — shows that opportunistic exploitation attempts usually start soon after a flaw becomes public, targeting exactly the sites that haven't updated yet.

What to do right now if you run Elementor Pro

If your site uses Elementor Pro, here are the steps Patchstack recommends, and they're worth following without delay:

  • Update to Elementor Pro 4.2.2 or later immediately, without waiting for your next scheduled maintenance window.
  • Check the wp-content/uploads/elementor/forms/ directory for any PHP files you don't recognize: updating the plugin fixes the flaw going forward, but it doesn't remove any malicious file that may have already been uploaded before the patch was applied.
  • If your site was running a vulnerable version for an extended period, it's worth doing a broader review of that uploads directory rather than just a quick glance.

Why this matters especially for small businesses in Spain

WordPress with Elementor is one of the most common combinations for small businesses and freelancers in Spain building their own site: it's visual, requires no coding, and works well for most use cases. The problem is that, precisely because of that, almost nobody is keeping an eye on whether a critical update for a specific plugin is available this week. It isn't just WordPress, either: the same "update now, even if your site is working fine" pattern showed up in other stacks too, as we saw with the critical Next.js vulnerabilities earlier this year.

This is exactly what active IT maintenance covers: someone keeping track of the security advisories for the plugins your site relies on, and applying patches before they turn into a real problem. Our IT maintenance service includes this kind of monitoring, and if you want a one-off diagnosis of where your installation stands right now, our website audit checks plugin versions, configuration, and any traces of past compromise.

Does your WordPress site run Elementor Pro?

We check your plugin versions, apply pending updates, and look for suspicious files on your server.

No spam. No sales calls. Just your personalised reply.