20/08/2026
🚨 Critical Elementor Pro security vulnerability — CVSS 9.0
A critical unauthenticated remote code ex*****on vulnerability has been discovered in Elementor Pro (CVE-2026-32475).
The flaw affects the Forms module's file upload functionality and could allow an attacker with no login required to upload a malicious PHP file and gain remote code ex*****on.
This is one you really shouldn't ignore.
Why it matters:
→ No authentication is required, meaning attacks can be automated and widespread.
→ Premium plugins aren't always automatically updated, so sites can remain vulnerable for some time.
→ The vulnerability affects Elementor Pro 4.2.1 and below.
If you're running Elementor Pro, update to 4.2.2 as soon as possible. Don't wait for your normal maintenance window.
Already protected?
If your website is covered by BWF's WordPress Maintenance Service with Patchstack, you're already protected. Patchstack provides virtual patching while the update is being rolled out, so there is no need to panic.
But please don't use that as a reason to ignore the update. Virtual patching is an important layer of protection, but keeping Elementor Pro fully up to date is still the right thing to do.
If you're using WP Umbrella as part of your BWF WordPress Maintenance package, we have already pushed the 4.2.2 update across your sites.
Stay safe. 🔒