On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. Exploitation requires the site to have published a page containing an Elementor Pro Form widget with at least one File Upload field that is not marked as required.
Props to Austin Ginder who discovered and responsibly reported this vulnerability through the Wordfence
Click here to continue reading this article.
