Elementor Under Attack: What Small Business Owners Need to Know This Week

It’s been a busy week for WordPress security. Attackers are actively exploiting a serious flaw in one of the most widely used website-building plugins around, a separate backup plugin used by millions of sites is still mostly unpatched, and researchers caught a fake plugin quietly planting backdoors. There’s some good news too, if you run an online shop. Here’s what happened and what it means for you.

A hugely popular page builder is being actively hacked

If your website was built with Elementor Pro, one of the most popular tools for designing WordPress sites without touching code, this one’s important. Security researchers found a serious flaw in how the plugin handles file uploads through its forms, and attackers wasted no time exploiting it, using it to sneak malicious files onto vulnerable sites and take them over completely. A fix went out on 19 August, but security firms have already blocked over 190,000 attack attempts since, which tells you how many sites are still exposed. Why it matters: Elementor is used on millions of websites, including a lot of small business sites built by freelancers and agencies. If you’re not sure whether your site (or your web designer’s build) is on the latest version, it’s worth asking.

Millions of sites still running a vulnerable backup plugin

All-in-One WP Migration and Backup, a plugin used to back up and move WordPress sites, has a flaw that lets attackers slip malicious code in during a restore, potentially handing them control of the whole site. It affects more than 3 million websites. A fix has been available for a couple of weeks, but as of this month, roughly two-thirds of sites running the plugin still hadn’t installed it. Why it matters: backup tools are meant to protect your site, so it’s an uncomfortable one to see left unpatched. If this plugin sounds familiar, it’s worth checking you’re on the current version rather than assuming it updates itself.

A fake plugin was caught hiding a backdoor

Researchers also found something sneakier doing the rounds: a plugin calling itself DebugMaster Pro, dressed up as a handy debugging tool, that actually plants a hidden backdoor for attackers to let themselves back in later, even after a site’s been “cleaned up”. Why it matters: it’s a good reminder to only install plugins from trusted sources, like the official WordPress plugin directory or a reputable developer, and to be cautious of anything unfamiliar that turns up in your site’s plugin list.

Some good news: WooCommerce got faster

Not everything this week was about security. WooCommerce, the plugin behind a huge share of small online shops, released version 11.1 with some genuinely useful improvements: noticeably faster page loading, smoother handling of orders, and better product image galleries for customers browsing on mobile. Why it matters: if you run a WooCommerce store, keeping the plugin updated isn’t just about security, it’s also the easiest way to get performance improvements like this without lifting a finger yourself.

The takeaway

Every story this week comes back to the same simple fix: keep WordPress, your theme and your plugins updated, only install plugins from sources you trust, and make sure someone is actually checking these things regularly rather than hoping the little “update available” notice gets noticed. If that’s not something you have time to stay on top of, that’s exactly what our WordPress Maintenance service is for, we keep your site patched, backed up and monitored so you don’t have to think about it. Take a look here: https://simplicity.digital/services/wordpress-maintenance/

← Back to Blog