Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Elementor Pro Plugin Could Let Hackers Take Control

A serious security weakness has been found in the Elementor Pro plugin used on WordPress websites. This flaw could allow attackers to upload harmful files and take control of the website without needing to log in. This matters because many small businesses use WordPress with Elementor Pro to manage their websites, and an attack could lead to data loss, website downtime, or damage to reputation.

20 August 2026

Reference: CVE-2026-32475

1. What is being reported?

The Elementor Pro plugin for WordPress has a vulnerability that lets attackers upload dangerous files, such as malicious code, without restrictions. This means someone could add harmful software to your website that runs commands remotely, potentially taking over your site.

2. What this means in plain English

If your website uses Elementor Pro, attackers might be able to break in and control your site, steal information, or disrupt your online presence. This is especially risky because the attack can happen without needing a username or password.

3. Could this affect a small business?

Small businesses using WordPress with the Elementor Pro plugin version 4.2.1 or earlier could be affected. If you do not use Elementor Pro or do not run a WordPress website, this vulnerability does not apply to you.

4. What to do now

  • Check if your website uses the Elementor Pro plugin and note its version.
  • Contact your website manager or IT provider to update Elementor Pro to the latest version as soon as possible.
  • If you cannot update immediately, ask your IT provider about temporary security measures to block unauthorised file uploads.
  • Review your website for any unusual activity and ensure regular backups are in place.

5. Ask your IT provider

Can you confirm if our website uses Elementor Pro version 4.2.1 or earlier, and if so, can you update it immediately to fix the critical security vulnerability CVE-2026-32475?

6. Bottom line

Update Elementor Pro on your WordPress site promptly to prevent hackers from taking control through this critical flaw.

Information based on CISA KEV, NVD, and reputable security news reporting.

Back to Vulnerability Briefs