The Maivia Gazette

Verified AI news, every morning

Security

Critical Elementor Pro upload flaw under active exploitation on WordPress sites

Wordfence has blocked almost 200,000 attempts to abuse CVE-2026-32475, which lets attackers plant a PHP webshell through a form's file-upload field.

An illustration of a dark tendril slipping through a form's envelope slot into a building's foundation.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

A recently patched critical vulnerability in the Elementor Pro plugin for WordPress, tracked as CVE-2026-32475, is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server, BleepingComputer reported. Elementor Pro has more than 6 million active installations and provides a drag-and-drop website builder. The flaw was patched on August 19. Since then, Defiant's Wordfence web application firewall has blocked almost 200,000 exploitation attempts against its clients. Wordfence said exploitation activity began on August 19, the same day the fix was released. The issue stems from faulty validation of file-upload arrays in Elementor Pro forms and is present in versions 4.2.1 and earlier. By submitting an empty file as the first array element and a malicious PHP file as the second, an attacker can cause the plugin to stop validating subsequent files. The uploaded payload is stored under the plugin's forms upload directory and can then be accessed to run commands remotely. WordPress security platform Patchstack warned last month that the bug could be used to upload arbitrary PHP files and trigger code execution. Exploitation is only possible when a site has a published Elementor Pro Form widget containing at least one File Upload field, which the report describes as a common configuration. Site owners running affected versions should update immediately and inspect the uploads directory for unexpected PHP files.

Sources

  1. BleepingComputerCritical Elementor Pro flaw exploited to take over WordPress sitesPublished · fetched

Also in this edition