Hackers are exploiting CVE-2026-32475, a critical arbitrary file upload flaw in Elementor Pro that can let unauthenticated attackers upload and run PHP payloads on WordPress sites. Defiant says exploitation began soon after the August 19 patch, with more than 190,000 blocked attempts and many sites still running vulnerable versions. #ElementorPro #CVE-2026-32475 #Defiant
Keypoints
- CVE-2026-32475 affects Elementor Pro versions up to 4.2.1.
- The flaw allows arbitrary file uploads through the Form widget.
- An empty upload slot can stop validation and let a PHP file pass unchecked.
- Attackers can achieve remote code execution and full site compromise.
- Defiant has blocked over 190,000 exploit attempts, and admins should upgrade to 4.2.2 and inspect the uploads directory.
Read More: https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/