← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 2, 2026 · 15:11via Malware.news

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

Brief

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro , a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover.

The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability .

Read more on Malware.news