Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

A Critical Elementor Pro Vulnerability Has Been Exploited to Hack Thousands of WordPress Sites

A highly critical vulnerability in the popular Elementor Pro WordPress plugin has been actively exploited by hackers to compromise thousands of websites. The bug, tracked as CVE-2026-32475, allows attackers to upload and execute malicious PHP code on a website’s server, potentially leading to full site takeover.

Elementor is a widely used drag-and-drop website builder with over 10 million installations. Its paid version, Elementor Pro, offers additional features, including a Form widget that supports File Upload fields. However, the plugin has been found to contain a flaw in its form submission handling mechanism. Specifically, when an upload field contains multiple parts, including an empty slot and a malicious PHP payload, the validation process is bypassed, allowing the attacker-supplied file to be written to disk without any checks.

The vulnerability, which was patched in version 4.2.2 on August 19, impacts all Elementor Pro plugin versions up to 4.2.1. According to Defiant, a WordPress security firm that has been tracking the issue, threat actors started exploiting the flaw immediately after the patch was released. The company has blocked over 190,000 exploit attempts to date.

The severity of this vulnerability is underscored by the fact that it allows an unauthenticated attacker to request and execute their PHP payload on the server. This could lead to full site compromise, including data theft, defacement, or even use of the website as a proxy for malicious activities. Site administrators are advised to check the /wp-content/uploads/elementor/forms/ directory for any suspicious files, which may indicate compromise.

Moreover, it’s essential to note that over two-thirds of Elementor’s 10 million installations run a vulnerable plugin version, according to WordPress data. This means that thousands of websites could be at risk of exploitation. Site owners should update their plugins to the latest version (4.2.2) as soon as possible and monitor their sites for any signs of compromise.

In light of this incident, it’s essential for website administrators to regularly review their plugin versions and ensure they are up-to-date with the latest security patches. Regular backups and monitoring can also help detect potential issues early on. By taking proactive measures to secure your website, you can protect yourself against such vulnerabilities and prevent unauthorized access to your site.


Source: SecurityWeek — 2026-09-05