What You Need to Know
A critical security vulnerability in Elementor Pro, the popular WordPress page builder plugin with over 6 million active installations, is currently being actively exploited by attackers. The Wordfence firewall has already blocked over 190,000 exploit attempts targeting this vulnerability, making it one of the most significant WordPress security threats in recent months.
If your website uses Elementor Pro, this is a must-read.
Understanding the Vulnerability (CVE-2026-32475)
The vulnerability, tracked as CVE-2026-32475, is an Unauthenticated Arbitrary File Upload flaw that allows attackers to upload malicious PHP files to your server without needing any credentials. It carries a critical CVSS score of 9.0, reflecting its severity.
How the attack works:
The vulnerability exists in the Elementor Pro Form widget’s handling of File Upload fields. When a File Upload field is not marked as required, a flaw in the field’s validation routine causes the extension and file type checks to be skipped entirely.
Attackers exploit this by submitting the file upload field as an array. The first element contains an empty filename, which triggers a validation bypass. The second element then carries the malicious .php file, which is written directly to the server.
The result: An attacker can upload a PHP webshell to your site, execute arbitrary commands, and achieve complete site takeover; all without needing a username or password.
What makes this vulnerability particularly dangerous is that it requires no authentication. Any visitor to your site can exploit it.
Attackers Are Actively Targeting This Vulnerability
According to Wordfence’s threat intelligence, attackers began targeting this vulnerability the same day it was publicly disclosed on August 19, 2026. The heaviest activity occurred between August 19th and 23rd.
Top offending IP addresses responsible for the most exploit attempts include:
| IP Address | Blocked Requests |
|---|---|
2602:fa59:10:7a1::1 | Over 28,000 |
185.196.220.85 | Over 23,800 |
103.84.230.85 | Over 23,600 |
103.90.148.202 | Over 15,300 |
216.126.225.208 | Over 15,000 |
167.254.240.75 | Over 8,100 |
167.254.241.119 | Over 7,700 |
114.10.17.253 | Over 6,100 |
These numbers illustrate the scale and urgency of the threat.
Are You at Risk?
Your site is vulnerable if:
- You are running Elementor Pro version 4.2.1 or earlier
- Your site has at least one published page containing an Elementor Pro Form widget with a non-required File Upload field
The good news: Elementor released a fully patched version (4.2.2) on August 19, 2026, the same day the vulnerability was disclosed.
What You Must Do Now
1. Update Elementor Pro Immediately
The single most critical action is to update your Elementor Pro plugin to version 4.2.2 or later
To update:
- Log in to your WordPress dashboard
- Navigate to Plugins → Installed Plugins
- Find Elementor Pro and click “Update Now”
2. Check for Indicators of Compromise
A successful attack results in a PHP file being written to the following directory:
/wp-content/uploads/elementor/forms/
This directory should never contain PHP files. We strongly recommend reviewing this directory and removing any unexpected .php files.
Also review your server access logs for requests to:
/wp-admin/admin-ajax.php?action=elementor_pro_forms_send_form
Pay special attention to requests originating from the IP addresses listed above.
3. Enable the Wordfence “Disable Code Execution for Uploads” Option
If you use Wordfence, ensure the “Disable Code Execution for Uploads directory” option is enabled in the Wordfence Global Options page. This provides an additional layer of protection against file upload attacks.
All Wordfence users are already protected against this vulnerability by the firewall’s built-in Malicious File Upload protection, including those running the free version.
Additional Resources
For a complete technical analysis of the vulnerability, read Wordfence’s detailed breakdown:
- Elementor Pro <= 4.2.1 – Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass
- Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin – Patchstack
- Elementor Pro RCE flaw CVE-2026-32475: patch to 4.2.2
How BG Cyber Connect Can Help
At BG Cyber Connect, we understand that keeping your WordPress site secure requires constant vigilance. Our team can:
- Perform an immediate security audit to verify your Elementor Pro version and identify any other vulnerabilities
- Review your site for indicators of compromise and remediate any infections
- Implement proactive security monitoring, including Web Application Firewall (WAF) protection
- Provide ongoing patch management to ensure critical updates are applied promptly
If you are unsure whether your site has been compromised or need assistance securing your WordPress installation, contact us immediately.
The Bottom Line
Update Elementor Pro to version 4.2.2 now. Over 190,000 exploit attempts have already been blocked, and attackers are actively scanning for vulnerable sites. Every day you delay increases the risk of a complete site takeover.
Need Help Securing Your WordPress Site?
Contact BG Cyber Connect for an Immediate Security Assessment
Explore our comprehensive WordPress security services:
BGCC Cybersecurity Solutions


