Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.