discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Critical Elementor Pro flaw exploited to take over WordPress sites

A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin is being actively exploited to upload webshells and execute arbitrary commands, affecting over 6 million installations. The flaw, patched on August 19, allows attackers to bypass file validati…

By Bill Toulas·Sep 3·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Critical Elementor Pro flaw exploited to take over WordPress sites
Image: bleepingcomputer.com

Attackers are actively exploiting a critical flaw in Elementor Pro, a popular WordPress plugin, to gain remote control over websites. The vulnerability, present in versions 4.2.1 and earlier, allows malicious PHP files to be uploaded via form fields, bypassing validation and enabling arbitrary command execution on affected servers.

Why it matters

This story matters to Security followers because it highlights the immediate threat posed by actively exploited critical vulnerabilities in widely used software, emphasizing the urgency of patching and the potential for widespread website compromise.

Imagine you have a special toy box where you can drop in your toys, but there's a tricky lock. Someone found a secret way to put a blank piece of paper in first, which makes the lock think everything else is fine, even if they then sneak in a secret note that tells your toy box to do bad things. Now, bad guys are using this trick to take over websites built with a popular tool called Elementor Pro, so it's super important for website owners to fix their toy boxes quickly!

Analysis

The active exploitation of CVE-2026-32475 in Elementor Pro represents a significant threat to a vast number of WordPress sites globally. Elementor Pro, with over 6 million active installations, is a cornerstone for many website builders due to its intuitive drag-and-drop interface. The vulnerability's nature, allowing for remote code execution, means that successful exploitation can lead to complete site takeover, data theft, or further malicious activities from the compromised server.

Elementor Pro

Elementor Pro is a widely adopted plugin that empowers WordPress users to design and customize their websites without extensive coding knowledge. Its popularity makes any critical vulnerability particularly impactful, as a single flaw can expose millions of sites. The vulnerability specifically targets the plugin's form functionality, which is a common feature on many business and personal websites, increasing the attack surface.

The issue stems from insufficient validation of file-upload arrays within Elementor Pro forms. Attackers can craft a specific request where an empty file is submitted as the first element in the array, followed by a malicious PHP file as the second. This sequence tricks the plugin into ceasing its validation process for subsequent files, allowing the malicious PHP payload to be uploaded undetected.

CVE-2026-32475

The technical mechanism behind CVE-2026-32475 is a validation bypass that leverages how Elementor Pro processes file uploads. Once the malicious PHP file is uploaded, it is stored in the /wp-content/uploads/elementor/forms/ directory under a randomly generated filename but retains the attacker-supplied .php extension. This location is typically used for legitimate form submissions, making the presence of a PHP file a clear indicator of compromise.

Attackers can then directly request this uploaded PHP file, triggering its execution on the server. This grants them the ability to run arbitrary commands, effectively giving them a webshell and full control over the compromised WordPress site. The vulnerability's ease of exploitation, requiring only a published Elementor Pro Form widget with a file upload field, makes it a high-risk threat.

Wordfence

Security firm Wordfence has been instrumental in tracking and reporting the exploitation attempts, observing a significant surge in activity shortly after the patch was released on August 19. Their web application firewall has blocked nearly 200,000 exploitation attempts targeting their clients, highlighting the widespread nature of the attacks. This rapid exploitation underscores the importance of immediate patching for critical vulnerabilities.

Wordfence also provided a list of IP addresses associated with thousands of attacks, enabling defenders to proactively block known malicious actors. Administrators are strongly advised to upgrade to Elementor Pro version 4.2.2 or later without delay. Furthermore, they should meticulously inspect the /wp-content/uploads/elementor/forms/ directory for any suspicious PHP files, as their presence is a definitive sign of compromise requiring immediate clean-up and incident response.

Key points

  • A critical vulnerability (CVE-2026-32475) in Elementor Pro versions 4.2.1 and earlier is being actively exploited.
  • The flaw allows attackers to bypass file upload validation in forms, enabling the upload of malicious PHP webshells.
  • Successful exploitation grants attackers remote code execution and arbitrary command control over WordPress sites.
  • Elementor released a patch (version 4.2.2) on August 19, the same day exploitation attempts began.
  • Defenders are urged to upgrade immediately and check the `/wp-content/uploads/elementor/forms/` directory for rogue PHP files.
The Upside

The vulnerability has been patched in Elementor Pro version 4.2.2, providing a clear path for administrators to secure their sites. Security firms like Wordfence are actively monitoring and blocking exploitation attempts, offering valuable insights and tools for defense.

The Downside

Given Elementor Pro's massive user base of over 6 million, a significant number of WordPress sites are likely still running vulnerable versions. The active exploitation means that unpatched sites face an immediate and high risk of compromise, potentially leading to widespread website takeovers.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpressvulnerabilityexploitpluginweb-securityremote-code-execution

Author

Bill Toulas

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 3, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpressvulnerabilityexploitpluginweb-securityremote-code-execution

Related

More from this desk

Sep 3·bleepingcomputer.com

French hospital fined €500,000 after data breach exposing 727,000 records

French hospital fined €500,000 for data breach exposing 727,000 records.

Sep 3·bleepingcomputer.com

Coder's registry infrastructure compromised to push malicious modules

Coder's Cloudflare infrastructure compromised, delivering malicious Terraform modules containing credential-stealing code.

Sep 3·bleepingcomputer.com

HPE patches critical ArubaOS-CX remote code execution flaw

HPE has patched a critical vulnerability in ArubaOS-CX that could lead to remote code execution.

Sep 3·thehackernews.com

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

This ThreatsDay report details a range of sophisticated cyberattacks, including CEO phishing kits, large-scale Dropbox account hacks, and OAuth traps, alongside 17 other security incidents.