Category: Security

  • Elementor Pro flaw is being exploited: patch to 4.2.2 today

    Elementor Pro flaw is being exploited: patch to 4.2.2 today

    Update Elementor Pro now. A critical flaw is being actively exploited in the wild, and the majority of installations are still unpatched.

    What the bug is

    Tracked as CVE-2026-32475 with a CVSS score of 9.8, the issue is an arbitrary file upload in the function that handles form submissions. That is about as bad as it gets: it leads to remote code execution.

    Who is affected

    • All Elementor Pro versions up to and including 4.2.1.
    • Patched in 4.2.2, released 19 August 2026.
    • Roughly two thirds of Elementor’s ~10 million installations were still running a vulnerable version as of 4 September.

    The free plugin is not affected

    This is a Pro-only vulnerability. It sits in form submission handling, which the free plugin does not ship. If you only run Elementor free, you are not exposed to this particular CVE. Check your version anyway.

    What to do

    Update to 4.2.2 or later today. If you cannot update immediately, disable Elementor Pro forms and audit wp-content/uploads for unexpected PHP files.

    Source: SecurityWeek.

  • Two more RCE bugs: All-in-One WP Migration and Forminator

    Two more RCE bugs: All-in-One WP Migration and Forminator

    Two more remote code execution bugs worth your afternoon, both in plugins with very large install bases.

    All-in-One WP Migration: CVE-2026-19949

    A second-order SQL injection in the archive restore functionality, CVSS 8.8, exposing more than 3 million sites to remote code execution. ServMask shipped a fix in version 7.110 on 20 August 2026.

    Backup and migration plugins are a particularly attractive target: they run with high privileges and routinely handle attacker-supplied archives. If you keep one installed permanently for occasional migrations, consider deactivating it between jobs.

    Forminator Forms: CVE-2026-15748

    An arbitrary file upload in handle_file_upload, CVSS 9.8. Insufficient file type validation allows unauthenticated attackers to upload executable files.

    The pattern

    All three of this month’s critical WordPress CVEs, including the Elementor Pro one, are file upload or input validation failures in code that accepts submissions from the public internet. If a plugin takes uploads from unauthenticated visitors, it deserves a much closer look than the rest of your stack.

    Sources: SecurityWeek on All-in-One WP Migration, SecurityWeek on Forminator.

  • Plugin Security Roundup – April 2026

    Several important plugin updates were released in early April 2026. Here’s what you need to patch immediately.

    Critical Updates

    • WooCommerce Subscriptions 8.6.0 – Security patches included
    • Yoast SEO – XSS vulnerability fixed
    • Wordfence Security – New firewall rules

    How to Stay Secure

    1. Enable auto-updates for trusted plugins
    2. Use a security plugin (Wordfence, Sucuri)
    3. Regular backups – daily if possible
    4. Monitor via vulnerability alerts
    5. Use strong passwords and 2FA

    Security Audit for Your Site?

    If you’re unsure about your site’s security posture, a professional audit can identify vulnerabilities before they’re exploited. Contact us for a security review.