Serious Vulnerability in Elementor Pro Used to Compromise WordPress Websites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Critical Vulnerability in Elementor Pro Plugin Under Active Exploitation

A newly addressed critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is currently being exploited by cyber adversaries to deploy webshells and execute arbitrary commands on affected servers.

Elementor Pro boasts over 6 million active installations and is widely utilized for its intuitive drag-and-drop website building interface.

This vulnerability was remediated on August 19, with Defiant’s Wordfence web application firewall blocking nearly 200,000 exploitation attempts aimed at its clientele since that date.

The heart of the issue lies in the improper validation of file-upload arrays within Elementor Pro forms, particularly affecting versions 4.2.1 and earlier.

By submitting an empty file as the initial array element while placing a malicious PHP file as the second element, attackers can circumvent validation processes for subsequent files.

The malicious payload, once uploaded, is stored under /wp-content/uploads/elementor/forms/ and can subsequently be accessed to facilitate remote command execution.

Cybersecurity platform Patchstack previously cautioned that this vulnerability could be leveraged to upload arbitrary PHP files, allowing for PHP code execution on the server.

Exploitation is viable only when a site features an active Elementor Pro Form widget with at least one file upload field—an increasingly common configuration.

On August 19, coinciding with Elementor’s release of version 4.2.2, which rectified the vulnerability, Wordfence reported a surge in exploitation attempts targeting CVE-2026-32475.

“The attacker submits the form’s File Upload field as an array, where the first element is empty and the second element carries a PHP payload with a .php filename, which is the structure that triggers the validation bypass,” states Wordfence.

“Once the uploaded PHP file is created, it resides in the /wp-content/uploads/elementor/forms/ directory under a randomly generated filename with the attacker-supplied .php extension, enabling the attacker to directly invoke it and execute arbitrary commands on the server,” notes the security firm.

Between August 19 and 23, Wordfence recorded a notable escalation in attack activity, blocking over 190,000 attempts at exploitation.

A computer monitor displaying the Wordfence security dashboard sits on a desk in a server room, with a keyboard and coffee cup nearby.

They have also compiled a list of IP addresses responsible for initiating thousands of attacks for administrators to add to their blocklists.

Administrators are strongly advised to upgrade to Elementor Pro version 4.2.2 or later without delay and to scrutinize the /wp-content/uploads/elementor/forms/ directory for any unauthorized PHP files.

Given that this directory is designated for storing uploaded form submissions, any presence of a PHP file serves as a significant indicator of compromise and should prompt immediate remediation efforts.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading