Critical Elementor Pro Vulnerability Under Active Exploitation

A critical security vulnerability in Elementor Pro, the popular WordPress page builder plugin with over 6 million active installations, is currently being actively exploited. The vulnerability (CVE-2026-32475) allows unauthenticated attackers to upload malicious PHP files and achieve complete site takeover. Over 190,000 exploit attempts have already been blocked. Update to version 4.2.2 immediately.
Vector illustration of a hooded hacker and thief stealing data from a laptop displaying a WordPress dashboard.

What You Need to Know

A critical security vulnerability in Elementor Pro, the popular WordPress page builder plugin with over 6 million active installations, is currently being actively exploited by attackers. The Wordfence firewall has already blocked over 190,000 exploit attempts targeting this vulnerability, making it one of the most significant WordPress security threats in recent months.

If your website uses Elementor Pro, this is a must-read.

Understanding the Vulnerability (CVE-2026-32475)

The vulnerability, tracked as CVE-2026-32475, is an Unauthenticated Arbitrary File Upload flaw that allows attackers to upload malicious PHP files to your server without needing any credentials. It carries a critical CVSS score of 9.0, reflecting its severity.

How the attack works:

The vulnerability exists in the Elementor Pro Form widget’s handling of File Upload fields. When a File Upload field is not marked as required, a flaw in the field’s validation routine causes the extension and file type checks to be skipped entirely.

Attackers exploit this by submitting the file upload field as an array. The first element contains an empty filename, which triggers a validation bypass. The second element then carries the malicious .php file, which is written directly to the server.

The result: An attacker can upload a PHP webshell to your site, execute arbitrary commands, and achieve complete site takeover; all without needing a username or password.

What makes this vulnerability particularly dangerous is that it requires no authentication. Any visitor to your site can exploit it.

Attackers Are Actively Targeting This Vulnerability

According to Wordfence’s threat intelligence, attackers began targeting this vulnerability the same day it was publicly disclosed on August 19, 2026. The heaviest activity occurred between August 19th and 23rd.

Top offending IP addresses responsible for the most exploit attempts include:

IP AddressBlocked Requests
2602:fa59:10:7a1::1Over 28,000
185.196.220.85Over 23,800
103.84.230.85Over 23,600
103.90.148.202Over 15,300
216.126.225.208Over 15,000
167.254.240.75Over 8,100
167.254.241.119Over 7,700
114.10.17.253Over 6,100

These numbers illustrate the scale and urgency of the threat.

Are You at Risk?

Your site is vulnerable if:

  • You are running Elementor Pro version 4.2.1 or earlier
  • Your site has at least one published page containing an Elementor Pro Form widget with a non-required File Upload field

The good news: Elementor released a fully patched version (4.2.2) on August 19, 2026, the same day the vulnerability was disclosed.

What You Must Do Now

1. Update Elementor Pro Immediately

The single most critical action is to update your Elementor Pro plugin to version 4.2.2 or later

To update:

  • Log in to your WordPress dashboard
  • Navigate to Plugins → Installed Plugins
  • Find Elementor Pro and click “Update Now”

2. Check for Indicators of Compromise

A successful attack results in a PHP file being written to the following directory:

/wp-content/uploads/elementor/forms/

This directory should never contain PHP files. We strongly recommend reviewing this directory and removing any unexpected .php files.

Also review your server access logs for requests to:

/wp-admin/admin-ajax.php?action=elementor_pro_forms_send_form

Pay special attention to requests originating from the IP addresses listed above.

3. Enable the Wordfence “Disable Code Execution for Uploads” Option

If you use Wordfence, ensure the “Disable Code Execution for Uploads directory” option is enabled in the Wordfence Global Options page. This provides an additional layer of protection against file upload attacks.

All Wordfence users are already protected against this vulnerability by the firewall’s built-in Malicious File Upload protection, including those running the free version.

Additional Resources

For a complete technical analysis of the vulnerability, read Wordfence’s detailed breakdown:

How BG Cyber Connect Can Help

At BG Cyber Connect, we understand that keeping your WordPress site secure requires constant vigilance. Our team can:

  • Perform an immediate security audit to verify your Elementor Pro version and identify any other vulnerabilities
  • Review your site for indicators of compromise and remediate any infections
  • Implement proactive security monitoring, including Web Application Firewall (WAF) protection
  • Provide ongoing patch management to ensure critical updates are applied promptly

If you are unsure whether your site has been compromised or need assistance securing your WordPress installation, contact us immediately.

The Bottom Line

Update Elementor Pro to version 4.2.2 now. Over 190,000 exploit attempts have already been blocked, and attackers are actively scanning for vulnerable sites. Every day you delay increases the risk of a complete site takeover.

Need Help Securing Your WordPress Site?

Contact BG Cyber Connect for an Immediate Security Assessment

Explore our comprehensive WordPress security services:
BGCC Cybersecurity Solutions

WordPress logo on a cracked red background opposed by a cyber security shield with a padlock representing website protection

Critical WordPress Core Vulnerability

On July 17, 2026, the WordPress Security Team released urgent security updates addressing a critical vulnerability chain in WordPress core affecting versions 6.8 through 7.0.1. Two flaws, CVE-2026-60137 (SQL Injection) and CVE-2026-63030 (Remote Code Execution), can be chained to allow unauthenticated attackers to take complete control of vulnerable sites. No plugins required. No authentication needed. Update to 6.8.6, 6.9.5, or 7.0.2 immediately.

Read More »

Schedule Appointment

Book Now!