A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, is being actively exploited to upload webshells and run arbitrary commands on WordPress servers. Defiant’s Wordfence has blocked nearly 200,000 attempts since the patch on August 19, and administrators should upgrade to Elementor Pro 4.2.2 or later and inspect the uploads directory for rogue PHP files. #CVE-2026-32475 #ElementorPro #Wordfence
Keypoints
- CVE-2026-32475 affects Elementor Pro 4.2.1 and earlier.
- The flaw comes from faulty validation of File Upload arrays in Elementor Pro forms.
- Attackers can bypass validation by submitting an empty file first and a PHP payload second.
- Exploited uploads are stored in /wp-content/uploads/elementor/forms/ and can be used for command execution.
- Wordfence has blocked almost 200,000 exploitation attempts since August 19.