Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A Critical Flaw in Elementor Pro Puts Millions of WordPress Sites at Risk of Remote Code Execution

A newly discovered vulnerability in the popular Elementor Pro plugin for WordPress has left millions of websites vulnerable to remote code execution attacks. The flaw, which affects all versions of Elementor Pro up to 3.16.1, allows unauthenticated attackers to upload PHP files and execute arbitrary code on affected sites.

The issue stems from a cross-domain privilege escalation vulnerability in the plugin’s settings API. When an attacker crafts a malicious request to the site’s server, they can bypass authentication checks and gain access to sensitive areas of the website. This enables them to upload any file type, including PHP scripts, which can then be executed on the server. The attack path is relatively straightforward: an attacker sends a specially crafted HTTP request to the site’s settings API, exploiting the flaw in Elementor Pro to elevate their privileges and gain control over the server.

The scope of this vulnerability is significant, with millions of WordPress sites potentially affected. Elementor Pro is one of the most widely used page builders for WordPress, and its popularity has made it a prime target for attackers seeking to exploit vulnerabilities in high-traffic websites. According to Elementor’s own estimates, their plugin is used on over 5 million active websites, making this vulnerability a major concern for site owners.

The fact that unauthenticated attackers can execute code on affected sites raises the stakes even higher. This type of attack is often used by threat actors seeking to gain a foothold in a target network or compromise sensitive data. In the worst-case scenario, an attacker could use this vulnerability to gain access to site databases, steal user credentials, or even inject malware into affected sites.

Site owners and administrators are advised to take immediate action to mitigate this risk. The first step is to update Elementor Pro to version 3.16.2 or later, which includes a fix for the identified vulnerability. Additionally, it’s essential to ensure that all plugins and themes on the site are up-to-date, as outdated software can create additional vulnerabilities that attackers can exploit.

To minimize the risk of falling victim to this type of attack, we recommend that site owners and administrators take proactive steps to harden their sites’ security posture. This includes regularly updating software, using strong passwords and two-factor authentication, and monitoring server logs for suspicious activity. By staying vigilant and taking these precautions, website owners can significantly reduce the likelihood of falling victim to remote code execution attacks like this one.


Source: The Hacker News — 2026-08-20