Feed›Vulnerability›Critical Elementor Pro flaw exploited to take over WordPress...
VulnerabilityBleeping Computer
9.0 — CRITICAL

Critical Elementor Pro flaw exploited to take over WordPress sites

📅 3 September 2026 at 14:52 UTC📰 Bleeping ComputerView original source ↗
Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A critical vulnerability in Elementor Pro, CVE-2026-32475, is being exploited to deliver webshell payloads and execute arbitrary commands on servers, putting WordPress sites at risk of compromise.

⚙️Technical Details
CVEs
CVE-2026-32475
Affected Systems
Elementor Pro plugin for WordPress
Attack Vectors
File Upload field in published Elementor Pro Form widget
💥Impact Assessment
Severity: critical
Who Is at Risk
WordPress site administrators and owners of sites with active Elementor Pro installations
🛡️Recommended Actions
1Upgrade to Elementor Pro 4.2.2 or later immediately
2Inspect the /wp-content/uploads/elementor/forms/ directory for rogue PHP files
3Implement additional security measures, such as web application firewalls and intrusion detection systems
📦Affected Products
Elementor Pro plugin for WordPress
🔐NVD Verified DataVERIFIED
CVE-2026-32475 ↗CVSS 9 — CRITICAL
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-434

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed