www.securityweek.com 9/5/2026, 1:31:04 PM · external

Elementor Pro Flaw Triggers 190,000 Exploit Attempts on WordPress Sites

Elementor Pro Flaw Triggers 190,000 Exploit Attempts on WordPress Sites
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical-severity vulnerability (CVE-2026-32475) has been identified in the Elementor Pro WordPress plugin, which allows unauthenticated attackers to upload malicious PHP files due to improper validation of file submissions. The vulnerability has a CVSS score of 9.8 and affects all versions up to 4.2.1. It was patched in version 4.2.2 on August 19. Over 190,000 exploits have been attempted following the release of the patch, and site owners are advised to check for signs of compromise in the uploads directory. Approximately two-thirds of Elementor's 10 million installations may still be using a vulnerable version.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline