A critical-severity vulnerability, tracked as CVE-2026-32475 with a CVSS score of 9.8, affects the Elementor Pro WordPress plugin, allowing an unauthenticated attacker to upload and execute arbitrary PHP files on the server via form submissions, potentially leading to full site compromise. The bug impacts all Elementor Pro plugin versions up to 4.2.1, which were patched in version 4.2.2 on August 19. Threat actors started exploiting this security defect immediately after the fixes landed, with over 190,000 exploit attempts blocked by Defiant. Site administrators are advised to check for PHP files stored in a specific directory and monitor logs for suspicious requests, as successful exploitation results in a PHP file being written to disk without validation, allowing an attacker to execute their payload on the server.
We recommend you to update Elementor Pro to version 4.2.2.[/subscribe_to_unlock_form]
A critical-severity vulnerability, tracked as CVE-2026-32475 with a CVSS score of 9.8, affects the Elementor Pro WordPress plugin, allowing an unauthenticated attacker to upload and execute arbitrary PHP files on the server via form submissions, potentially leading to full site compromise. The bug impacts all Elementor Pro plugin versions up to 4.2.1, which were patched in version 4.2.2 on August 19. Threat actors started exploiting this security defect immediately after the fixes landed, with over 190,000 exploit attempts blocked by Defiant. Site administrators are advised to check for PHP files stored in a specific directory and monitor logs for suspicious requests, as successful exploitation results in a PHP file being written to disk without validation, allowing an attacker to execute their payload on the server.
We recommend you to update Elementor Pro to version 4.2.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]