Vulnerability Management

Critical vulnerability in Elementor Pro exploited for RCE attacks

(Credit: Bilal Ulker – stock.adobe.com)

As reported by Bleeping Computer, a critical vulnerability (CVE-2026-32475) in the widely used Elementor Pro WordPress plugin is actively being exploited by attackers to execute arbitrary commands on vulnerable servers. The vulnerability affects Elementor Pro versions 4.2.1 and earlier.

The exploit targets a flaw in how Elementor Pro forms handle file uploads. Attackers can bypass validation by submitting an empty file as the first array element and a malicious PHP file as the second. This allows them to upload a webshell payload, typically stored in the /wp-content/uploads/elementor/forms/ directory. Once uploaded, this webshell can be accessed to execute arbitrary PHP code remotely on the compromised server. This vulnerability is particularly concerning as it affects a plugin with over 6 million active installations and is exploitable when a site uses Elementor Pro's File Upload field.

Since Elementor released version 4.2.2 on August 19 to patch the issue, security firms like Wordfence have blocked nearly 200,000 exploitation attempts. Administrators are urged to update to the latest version immediately and inspect their upload directories for suspicious PHP files, as this indicates a potential compromise.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds