CVE Tools

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

SecurityWeekBy Ionut Arghire

Reported exploitedElementor Pro WordPress Plugin

Our summary

Security firm Defiant reports active exploitation of a critical vulnerability identified as CVE-2026-32475 within the Elementor Pro WordPress plugin. This flaw, assigned a CVSS score of 9.8, allows unauthenticated attackers to bypass file validation by manipulating form submission arrays, enabling them to upload and execute malicious PHP payloads directly on the server.

All versions of Elementor Pro prior to 4.2.1 are affected, with the fix available in version 4.2.2 released on August 19. Because attackers began exploiting the issue immediately after the patch dropped, site administrators must update urgently. Defiant has already blocked over 190,000 attack attempts and advises users to inspect the /wp-content/uploads/elementor/forms/ directory for unauthorized PHP files and review logs for suspicious activity related to /wp-admin/admin-ajax.php.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store