< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Elementor Pro WordPress plugin vulnerability exploited by hackers

Hackers are exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to compromise websites. The flaw, tracked as CVE-2026-32475 with a CVSS score of 9.8, involves an arbitrary file upload issue within the plugin’s form submission function.

According to security firm Defiant, the vulnerability occurs when the validation loop encounters an empty upload slot, causing it to abort the validation of subsequent files in the same field. This allows an unauthenticated attacker to bypass security checks by submitting an array containing an empty slot followed by a PHP payload. Once the payload is written to the disk, the attacker can execute it on the server, potentially leading to full site compromise.

The vulnerability affects all versions of Elementor Pro up to 4.2.1. A patch was released in version 4.2.2 on August 19. Defiant reported that threat actors began exploiting the defect immediately following the release of the fix and has blocked over 190,000 exploit attempts to date. Site owners are urged to update to the latest version immediately.

Entities

Defiant · Elementor · WordPress