Critical Elementor Pro flaw exploited to take over WordPress sites
A critical vulnerability in Elementor Pro, a widely used WordPress plugin, is being actively exploited in the wild to take over WordPress sites, according to a report from BleepingComputer. The report, published on September 3, 2026, indicates that attackers are leveraging this flaw to gain unauthorized access to websites running the plugin. While the article does not specify the exact nature of the vulnerability or the affected version numbers, the exploitation is described as critical, suggesting a high severity. The consequence is that WordPress site owners using Elementor Pro are at risk of having their sites completely taken over by malicious actors. The report does not provide details on how the exploitation occurs or whether patches are available, but the active exploitation underscores the urgency for site administrators to be aware of the threat. The source text is limited, but it clearly states that the flaw is being exploited to take over WordPress sites, which is a serious security concern for the large user base of Elementor Pro.
WordPress sites using Elementor Pro are at risk of takeover due to an actively exploited critical flaw.