Threat Intelligence

Critical Elementor Pro Flaw Lets Hackers Take Over WordPress Sites Without Logging In

The Hacker News · 20 Aug 2026
Key Takeaway If your business website uses Elementor Pro, update the plugin to the latest patched version immediately and review your site for any signs of unauthorised file uploads.

Security researchers have disclosed a serious vulnerability in Elementor Pro, a popular WordPress plugin used by many small businesses to build and customise their websites. The flaw, tracked as CVE-2026-32475, has been given a near-maximum severity score of 9.0 out of 10, reflecting how easily and damagingly it could be exploited.

The issue lies in the plugin's Forms module, specifically in how it handles file uploads. Attackers do not need a username or password to exploit the flaw — they can potentially upload harmful PHP files disguised as legitimate uploads, which could then be executed to gain full control of the affected website. For a small business, this could mean a defaced site, stolen customer data, or the site being used to launch further attacks.

Because Elementor Pro is widely used across WordPress websites globally, this vulnerability poses a significant risk to any business relying on the plugin, particularly if it has not been updated recently. Website administrators should check their plugin version immediately and apply any available security patch as soon as possible.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.