CVE Tools

Critical Elementor Pro flaw exploited to take over WordPress sites

BleepingComputerBy Bill Toulas

Reported exploitedElementor ProWordPress

Our summary

Attackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin, identified as CVE-2026-32475, to gain remote command execution on affected servers. The flaw, which affects versions 4.2.1 and earlier, permits malicious PHP uploads by bypassing file-validation checks in form elements, resulting in webshell installation. Wordfence reports blocking approximately 200,000 related attack attempts since the fix was released on August 19. Site administrators should immediately update to Elementor Pro 4.2.2 or later and audit the /wp-content/uploads/elementor/forms/ directory for unauthorized files.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store