CVE Tools
Back to feed
Exploited in the wild Elementor Pro web-app WordPress Elementor rce

Critical Elementor Pro flaw exploited to take over WordPress sites

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Attackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin, identified as CVE-2026-32475, to gain remote command execution on affected servers. The flaw, which affects versions 4.2.1 and earlier, permits malicious PHP uploads by bypassing file-validation checks in form elements, resulting in webshell installation. Wordfence reports blocking approximately 200,000 related attack attempts since the fix was released on August 19. Site administrators should immediately update to Elementor Pro 4.2.2 or later and audit the /wp-content/uploads/elementor/forms/ directory for unauthorized files.