ON
← Back to feed
A vulnerability in the WordPress plugin Elementor Pro has exposed 6 million websites to the virus.
Germany🏛️ PoliticsCenter3 days ago

A vulnerability in the WordPress plugin Elementor Pro has exposed 6 million websites to the virus.

Ein Sicherheitsleck im WordPress-Plugin Elementor Pro ermöglicht unbefugten Nutzern das Hochladen beliebiger Dateien, einschließlich ausführbarer PHP-Dateien, was zu einer vollständigen Kontrolle über betroffene WordPress-Instanzen führen kann. Das Sicherheitsrisiko wurde vom IT-Sicherheitsunternehmen Wordfence gemeldet und als 'kritisch' eingestuft (CVSS 9.8). Die Schwachstelle resultiert aus einem Logikfehler in der Dateiüberprüfungsfunktion beim Upload von Formulardaten. Eine aktualisierte Version des Plugins (4.2.2) ist seit dem 19. August 2026 verfügbar. Ähnliche Sicherheitsprobleme wurden kürzlich auch in anderen populären WordPress-Plugins wie Forminator Forms und Royal Elementor Addons entdeckt.

A critical security flaw has been discovered in the widely used WordPress plugin Elementor Pro, potentially compromising six million websites. The vulnerability allows unauthorized attackers to upload arbitrary files, including executable PHP files, without prior authentication, posing a serious risk to affected sites. The issue was identified by cybersecurity firm Wordfence, which warned users of the potential for complete takeover of vulnerable WordPress installations through this exploit. The flaw stems from a logic error in the file upload validation process within Elementor Pro’s form widgets. Specifically, if a page contains an Elementor Pro form widget with at least one file upload field, even if it is not marked as required, an attacker could exploit the vulnerability. This weakness is catalogued under CVE-2026-32475 and carries a CVSS score of 9.8, indicating a high severity level. The vulnerability is rated as critical due to its potential to allow remote code execution. Wordfence disclosed the flaw after receiving it through its bug bounty program, where the researcher was awarded $15,600, a notably high sum that underscores the real-world impact of the vulnerability. The company informed the Elementor team in early July, and as of Wednesday, August 19, the patched version 4.2.2 is available for download. Administrators are urged to check whether their installations are already up to date and apply the update promptly to mitigate the risk. This discovery follows similar vulnerabilities found in other popular WordPress plugins such as Forminator Forms and Royal Elementor Addons. Both of these plugins have more than 600,000 active installations each, making them similarly susceptible to attacks involving unauthorized file uploads. In those cases, attackers could inject malicious code into websites without needing user credentials, leading to full system compromise. The widespread use of Elementor Pro makes this vulnerability particularly concerning. With over six million active installations, the potential attack surface is vast. If left unpatched, the flaw could enable cybercriminals to deploy malware, steal sensitive data, or take control of entire websites. The ease with which the exploit can be carried out further heightens the urgency for administrators to update their systems. Security experts recommend that all users of Elementor Pro immediately review their site configurations and ensure they are running the latest version of the plugin. Additionally, regular backups and monitoring for unusual activity should be part of routine website maintenance. While the availability of the updated version provides a clear path forward, the speed of adoption among users will determine how effectively the threat is mitigated. As the cybersecurity landscape continues to evolve, staying proactive in addressing known vulnerabilities remains essential for maintaining the integrity of web platforms.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 953 days ago
A vulnerability in the WordPress plugin Elementor Pro has exposed 6 million websites to the virus.

Ein Sicherheitsleck im WordPress-Plugin Elementor Pro ermöglicht unbefugten Nutzern das Hochladen beliebiger Dateien, einschließlich ausführbarer PHP-Dateien, was zu einer vollständigen Kontrolle über betroffene WordPress-Instanzen führen kann. Das Sicherheitsrisiko wurde vom IT-Sicherheitsunternehmen Wordfence gemeldet und als 'kritisch' eingestuft (CVSS 9.8). Die Schwachstelle resultiert aus einem Logikfehler in der Dateiüberprüfungsfunktion beim Upload von Formulardaten. Eine aktualisierte Version des Plugins (4.2.2) ist seit dem 19. August 2026 verfügbar. Ähnliche Sicherheitsprobleme wurden kürzlich auch in anderen populären WordPress-Plugins wie Forminator Forms und Royal Elementor Addons entdeckt.

Bias read (Center): Die Berichterstattung konzentriert sich rein auf technische Aspekte der Sicherheitslücke und deren Auswirkungen auf WordPress-Installationen. Es wird keine politische Einordnung oder Bewertung der Sicherheitsverantwortung durch Entwickler oder Regierungsbehörden vorgenommen. Die Quellen werden sachg

Why factuality (95): The article provides specific details such as the number of installations (over six million), the nature of the vulnerability (allowing unauthorized file uploads including executable PHP files), the CVE identifier (CVE-2026-32475), the CVSS score (9.8), and the patch version (4.2.2). These facts ali

Why objectivity (95): The article presents the information in a neutral manner, focusing on technical details and the actions taken by Wordfence and Elementor Pro. It avoids emotional language and does not favor any particular party.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories