News: Important Security Alert: Elementor Pro Is Being Actively Exploited
A critical security vulnerability has been discovered in the popular WordPress plugin Elementor Pro. This vulnerability, registered as CVE-2026-32475, is now being actively exploited.
Under certain circumstances, the vulnerability allows an unauthenticated attacker to upload arbitrary files to a WordPress website. These files may include executable PHP files.
Successful exploitation can result in Remote Code Execution (RCE) and ultimately a complete takeover of the affected WordPress website.
Which versions are vulnerable?
Affected versions:
Elementor Pro 4.2.1 and earlier
The vulnerability has been fixed in:
Elementor Pro 4.2.2 and later
Successful exploitation requires the affected website to have a published Elementor Pro Form widget containing at least one non-required File Upload field.
As active attacks are now being observed, we strongly advise all customers using Elementor Pro to immediately check their installed version and update it where necessary.
Action required
If you use Elementor Pro:
1. Log in to your WordPress administration area.
2. Check the installed version of Elementor Pro.
3. Immediately update Elementor Pro to version 4.2.2 or later.
4. Check WordPress Core, all other plugins and themes for available updates.
5. Check your website for unusual behaviour, unknown administrator accounts, modified files or other indications of compromise.
Updating Elementor Pro alone may not be sufficient if the website was already compromised before the update was installed. If in doubt, we recommend performing an additional malware and integrity check.
Responsibility for maintenance and updates
We would like to explicitly remind customers that with regular web hosting, VPS and server services, maintenance of WordPress, plugins, themes and other customer-installed software remains the customer’s own responsibility.
This does not apply where Managed WordPress maintenance is explicitly included as part of your Vservs service.
Without a Managed WordPress service, you are responsible for installing security updates in a timely manner and for maintaining and securing your WordPress installation.
The availability of a security update does not automatically mean that Vservs will install that update on your website.
Protecting our infrastructure and other customers
An outdated or compromised WordPress installation can affect more than just the website concerned. Compromised websites may be used for malware distribution, phishing, spam, attacks against third parties or further distribution of malicious software.
If we detect attacks, malware or other suspicious activity and our investigation shows that required security updates or regular maintenance have not been performed, Vservs reserves the right to temporarily disable or isolate the affected website(s) or service.
We may take this action when necessary to prevent further damage, abuse of our infrastructure or risks to other customers and systems.
Recovery and remediation work on non-managed websites and servers is not automatically included in our regular services.
If such an incident occurs outside our regular business hours, during a weekend or on a public holiday, investigation and remediation may – depending on severity and availability – be handled from the next business day. For an incident occurring during the weekend, this may mean that remediation will start on Monday.
Preventing a compromise is therefore considerably better than having to recover a compromised WordPress installation afterwards.
Managed WordPress Hosting
Would you prefer not to manage the technical maintenance of WordPress yourself?
With Vservs Managed WordPress Hosting, we take care of an important part of the technical maintenance, security updates, monitoring and management of your WordPress environment.
Please contact us if you would like to know which Managed WordPress solution best suits your website.
Need assistance?
If you use Elementor Pro and are unsure whether your website is secure, or if you suspect that your website may already have been affected, please contact us.
Vservs B.V.
Managed VPS · High Performance Hosting · Managed WordPress · Enterprise SSL
Independent Internet Service Provider