My friend, I compared your
Elementor Pro with my purchased copy, and yours its
nulled with a fake expiry for 2073 , but also contains a hidden image pointing to mykey.cu.ma. I checked that image endpoint, and it’s still active. It could be used to track requests from browsers (such as IP Address) opening the WordPress plugins page.
This doesn’t prove there’s a backdoor, but it’s definitely a bad addition. The full Link as I can see , is this:
https://mykey.cu.ma/track/stream.php?file=elementor.png in line 207 in elementor-pro.php
View attachment 58593