If you haven’t updated your Elementor Pro site to version 4.2.2 or greater then best to do so now. The vulnerability allows for a remote code execution, but requires Elementor Pro (not free) and a form widget with a file upload field. Details in the report.

