ALL SYSTEMS OPERATIONALUPTIME 99.97%FLEET 18/18IN-MUM · US-LAX · EU-FSN EST. 2003 · +91 11 4998 4038

KNOWLEDGEBASE · SECURITY

March 2022: Critical Remote Code Execution Vulnerability in Elementor

Last updated 2022-04-13

On March 29, 2022, the Wordfence Threat Intelligence team initiated the disclosure process for a critical vulnerability in the Elementor plugin that allowed any authenticated user to upload arbitrary PHP code.

Elementor is one of the most popular WordPress plugins and is installed on over 5 million websites.
A patched version of the plugin, 3.6.3, was released the next day on April 12, 2022.

Update your Elementor plugin to version 3.6.3 or later immediately

← All knowledgebase articles

Tell us what has to stay up.

A short conversation with an engineer. No quote-bot, no callback queue. We'll tell you honestly if we're not the right fit.