securityonline.info 9/2/2026, 4:47:28 PM · external

CVE-2026-32475: Elementor Pro RCE Exploited in the Wild

CVE-2026-32475: Elementor Pro RCE Exploited in the Wild
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, is being actively exploited, posing severe risks to over six million WordPress websites utilizing the plugin. The vulnerability, which allows arbitrary file uploads, carries a CVSS score of 9.8 and can lead to complete server compromise. Users are advised to update to version 4.2.2 immediately to mitigate risks.

Key attack details include the exploitation method via the Form widget's file upload fields, which enables unauthorized execution of code by attackers. The vulnerability affects Elementor Pro versions up to 4.2.1 and has seen a significant number of exploitation attempts reported by security researchers.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline