Security Brief: Elementor Pro Arbitrary File Upload

Wordfence reported an unauthenticated file-upload flaw in Elementor Pro (about 6 million installs). Attackers can upload PHP and take over the site. The issue is patched — update and review uploads this week.

Back to Blog

Illustration of a security breach in website plugins, highlighting an Elementor Pro vulnerability.

Wordfence reported an unauthenticated arbitrary file-upload flaw in Elementor Pro, a WordPress plugin with an estimated six million active installations. Attackers who never sign in can upload files, including PHP, which can lead to remote code execution and taking over the site. The issue has been patched; confirm your Elementor Pro version and review uploads this week.

What happened

On 24 July 2026, Wordfence received a report of the issue. Elementor Pro is a paid page-builder add-on used on millions of WordPress sites. The reported bug does not require a login. An attacker can place arbitrary files on the server, including executable PHP. That path can become remote code execution and full site control. Wordfence published the write-up on 20 August 2026 and said the vulnerability has been patched.

Why it matters for website owners

Any site running Elementor Pro is in scope, including marketing sites and stores that rely on the page builder. A PHP upload can add a backdoor, change content, and persist after you update the plugin. Check the plugin list this week and treat unexpected files in uploads as an incident.

What to check on your site

  • Confirm Elementor Pro is listed under Plugins and apply the latest vendor update. The Wordfence title states the flaw was patched; use your dashboard as the record of the version you run.
  • Review Media and the uploads directory for unexpected PHP or other executable files. Remove anything you did not place there.
  • Open Users and look for unexpected administrators. Reset owner and admin passwords if recent logins are unexplained.
  • Run a public WordPress profile with the Wordpress Stack Checker after you patch.
  • If you suspect the site was taken over, inventory hostnames with Subdomain Discovery, then test leftover DNS with the Subdomain Takeover Scanner.

Related reading

Sources