We are writing to inform you of a security vulnerability that was discovered in the Elementor Pro Form widget’s file upload field, which has been resolved in Elementor Pro 4.2.2, released August 19, 2026.
This vulnerability only exposes websites that use an Elementor Pro Form with an upload file form field, and the multiple file upload option enabled (it is disabled by default). If this applies to your site, make sure to update to the latest Elementor Pro version.
Every other Elementor site is unaffected, however we still recommend all sites update to the latest version to reduce the likelihood of security and incompatibility issues.
Comments
Post a Comment