Critical Elementor Pro flaw exploited to take over WordPress sites
What happened
Elementor Pro versions 4.2.1 and earlier are under active attack via CVE-2026-32475, a file-upload validation flaw that allows attackers to bypass security checks and deploy webshells. The vulnerability enables remote code execution by storing malicious PHP files in the `/wp-content/uploads/elementor/forms/` directory, a technique Wordfence has blocked in nearly 200,000 attempts since the August 19 patch. Administrators should upgrade to version 4.2.2 and inspect that directory for unauthorized PHP files to identify compromised systems.
Why it ranks #1
Elementor Pro versions 4.2.1 and earlier are under active attack via CVE-2026-32475, a file-upload validation flaw that allows attackers to bypass security checks and deploy webshells.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Upgrade to Elementor Pro 4.2.2 or later immediately and inspect the /wp-content/uploads/elementor/forms/ directory for rogue PHP files.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited