TL;DR
Attackers are actively exploiting a critical Elementor Pro vulnerability in the wild. Specifically, tracked as CVE-2026-32475, this bug holds a CVSS 9.8 score and allows dangerous file uploads. Therefore, website owners must update to version 4.2.2 immediately to prevent complete server compromise.
- CVE: CVE-2026-32475
- CVSS: 9.0 (Critical · CVSSv3)
- Product: Elementor Pro
- Affected: n/a
- Impact: WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
- Status: Exploited in the wild
- Patched in: 4.2.2
- EPSS: 2.4% (30-day)
- Action: Update to 4.2.2 now
Why It Matters
Over six million active websites use this popular WordPress plugin. Consequently, this huge install base offers a massive target for threat actors. Specifically, uninvited guests can run arbitrary code on the server without needing any special access. Ultimately, this full site takeover leads directly to data theft and network attacks. Attackers typically deploy web shells to keep their backdoor access open. Moreover, Wordfence researchers reported that “The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability.” Leaving this Elementor Pro vulnerability unpatched guarantees a severe security breach.
How the Attack Works
The bug resides within the Form widget’s handling of File Upload fields. Specifically, the flaw requires the target site to publish a page with a Form widget. This widget must contain at least one optional file upload field. First, hackers trigger a bypass by submitting the field as an array. Initially, they provide an empty file element. Consequently, the system encounters an error and returns early. This action skips all file type checks for the remaining items. The security advisory explained, “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.” Next, the second element carries the bad PHP payload. Then, the server writes this file into a public folder. The system uses a random filename. Finally, attackers request the file directly to run their commands.
Affected Versions
This critical flaw impacts Elementor Pro versions up to and including 4.2.1. Currently, hackers are actively exploiting it in the wild. Furthermore, experts note that attacks started the exact same day the bug became public on August 19, 2026. Overall, attackers have launched massive waves of requests targeting networks globally. The highest volume of attacks came from a small group of active IP addresses. Therefore, admins should inspect the /wp-content/uploads/elementor/forms/ folder for strange PHP files.
Patch or Mitigation Steps
Website owners must update their plugin to Elementor Pro version 4.2.2 immediately. Fortunately, developers released this fully patched version to fix the broken logic. Additionally, you must monitor your server logs for strange POST requests hitting the admin-ajax.php file. For further details, read the Wordfence security advisory to view the top attacking IP addresses. Finally, if you find any unexpected PHP files in your uploads folder, you must assume a full breach.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!