Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. Exploitation requires the site to have published a page containing an Elementor Pro Form widget with at least one File Upload field that is not marked as required.

This post was originally published on Wordfence by István Márton.

Follow us

Don't be shy, get in touch. We love meeting interesting people and making new friends.