20 August 2026
Reference: CVE-2026-32475
1. What is being reported?
The Elementor Pro plugin for WordPress has a vulnerability that lets attackers upload dangerous files, such as malicious code, without restrictions. This means someone could add harmful software to your website that runs commands remotely, potentially taking over your site.
2. What this means in plain English
If your website uses Elementor Pro, attackers might be able to break in and control your site, steal information, or disrupt your online presence. This is especially risky because the attack can happen without needing a username or password.
3. Could this affect a small business?
Small businesses using WordPress with the Elementor Pro plugin version 4.2.1 or earlier could be affected. If you do not use Elementor Pro or do not run a WordPress website, this vulnerability does not apply to you.
4. What to do now
- Check if your website uses the Elementor Pro plugin and note its version.
- Contact your website manager or IT provider to update Elementor Pro to the latest version as soon as possible.
- If you cannot update immediately, ask your IT provider about temporary security measures to block unauthorised file uploads.
- Review your website for any unusual activity and ensure regular backups are in place.
5. Ask your IT provider
Can you confirm if our website uses Elementor Pro version 4.2.1 or earlier, and if so, can you update it immediately to fix the critical security vulnerability CVE-2026-32475?
6. Bottom line
Update Elementor Pro on your WordPress site promptly to prevent hackers from taking control through this critical flaw.
Information based on CISA KEV, NVD, and reputable security news reporting.