THREATOPS
THREAT OPSThreat News › Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

medwordfencePublished 2026-09-02

<p>On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://elementor.com/pro/" rel="noopener" target="_blank">Elementor Pro</a>, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulne

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/