Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Elementor Pro: Critical Flaw Actively Exploited to Hijack WordPress Sites

A critical vulnerability in the widely used WordPress plugin Elementor Pro (CVE-2026-32475, CVSS 9.0) has been under active exploitation since 19 August 2026 – attackers plant PHP webshells and take over entire websites. Security firm Wordfence reported on 3 September that its web application firewall had blocked nearly 190,000 attack attempts since then.

How the attack works

The root cause is faulty validation of file uploads in the plugin’s forms. When an attacker submits the upload field as an array – with an empty file as the first element and a malicious PHP file as the second – Elementor Pro stops validating the following files. The payload lands in /wp-content/uploads/elementor/forms/ and can then be called directly to run arbitrary commands on the server. No authentication is required.

Affected versions and reach

All Elementor Pro versions up to and including 4.2.1 are vulnerable. The vendor closed the hole on 19 August with version 4.2.2. The plugin runs on more than six million websites, making the potential attack surface enormous. Because Elementor Pro is a paid add-on distributed outside the official WordPress repository, automatic updates often do not apply reliably. Many operators therefore remain unpatched – an easy target for the mass scans, which according to Wordfence peaked around 23 August.

What to do now

  • Update to Elementor Pro 4.2.2 or later immediately.
  • Inspect the /wp-content/uploads/elementor/forms/ directory for unknown PHP files.
  • If compromise is suspected, preserve logs and scan the site for backdoors.

Sources: BleepingComputer, The Hacker News, SC Media

Mastodon
Scroll to Top