A critical-severity vulnerability (CVE-2026-32475) has been identified in the Elementor Pro WordPress plugin, which allows unauthenticated attackers to upload malicious PHP files due to improper validation of file submissions. The vulnerability has a CVSS score of 9.8 and affects all versions up to 4.2.1. It was patched in version 4.2.2 on August 19. Over 190,000 exploits have been attempted following the release of the patch, and site owners are advised to check for signs of compromise in the uploads directory. Approximately two-thirds of Elementor's 10 million installations may still be using a vulnerable version.
Elementor Pro Flaw Triggers 190,000 Exploit Attempts on WordPress Sites
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Elementor Pro Flaw Triggers 190,000 Exploit Attempts on WordPress Sites
www.securityweek.com
-
CVE-2026-32475: Elementor Pro RCE Exploited in the Wild
securityonline.info
-
Critical CVE-2026-32475 Flaw Hits 6 Million WordPress Sites
securityonline.info