As reported by Bleeping Computer, a critical vulnerability (CVE-2026-32475) in the widely used Elementor Pro WordPress plugin is actively being exploited by attackers to execute arbitrary commands on vulnerable servers. The vulnerability affects Elementor Pro versions 4.2.1 and earlier.The exploit targets a flaw in how Elementor Pro forms handle file uploads. Attackers can bypass validation by submitting an empty file as the first array element and a malicious PHP file as the second. This allows them to upload a webshell payload, typically stored in the /wp-content/uploads/elementor/forms/ directory. Once uploaded, this webshell can be accessed to execute arbitrary PHP code remotely on the compromised server. This vulnerability is particularly concerning as it affects a plugin with over 6 million active installations and is exploitable when a site uses Elementor Pro's File Upload field.Since Elementor released version 4.2.2 on August 19 to patch the issue, security firms like Wordfence have blocked nearly 200,000 exploitation attempts. Administrators are urged to update to the latest version immediately and inspect their upload directories for suspicious PHP files, as this indicates a potential compromise.Source: Bleeping Computer
Vulnerability Management
Critical vulnerability in Elementor Pro exploited for RCE attacks
(Credit: Bilal Ulker – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
