THREATOPS
THREAT OPSThreat News › Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

medwordfencePublished 2026-08-20

<p>On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in <a href="https://elementor.com/pro/" rel="noopener" target="_blank">Elementor Pro</a>, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vul

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/08/critical-arbitrary-file-upload-vulnerability-patched-in-elementor-pro-wordpress-plugin/