Cybersecurity
Elementor Pro flaw exploited against WordPress sites
Elementor Pro for WordPress was patched on 19 August, but Wordfence said attackers began using the flaw the same day and had triggered nearly 200,000 blocked attempts.
- Elementor Pro versions 4.2.1 and earlier contained CVE-2026-32475 in file-upload validation.
- Elementor released version 4.2.2 on 19 August to address the flaw.
- Wordfence said it blocked almost 200,000 exploitation attempts and later said the activity started on 19 August.
- Patchstack warned last month that the issue could allow arbitrary PHP upload and code execution, and administrators were told to update and check the uploads directory.
Elementor Pro for WordPress contained CVE-2026-32475 in versions 4.2.1 and earlier. Elementor patched the issue on 19 August in version 4.2.2.
The vulnerability was in validation for file uploads submitted through forms. The article said an attacker could send an empty first array item and a malicious PHP file as the second, which stopped later files from being checked.
Wordfence, which Defiant runs, said it had blocked almost 200,000 exploitation attempts against its customers. It said the activity began on 19 August and ran through 23 August.
Patchstack warned last month that the flaw could let attackers upload arbitrary PHP files and execute code on the server. Administrators were told to upgrade to Elementor Pro 4.2.2 or later and inspect /wp-content/uploads/elementor/forms/ for suspicious PHP files.
Named in this story
Companies
- Elementor
- released version 4.2.2 that fixed the issue
- Defiant
- runs Wordfence and said it blocked the attacks
- Patchstack
- warned that the flaw could let attackers upload PHP files and run code
Products and systems
- Elementor Pro
- the WordPress plugin containing the flaw
- WordPress
- the platform the plugin runs on
- Wordfence
- the firewall that blocked exploitation attempts and reported the activity
How the source tells it
The source was mainly a technical advisory, but it leaned into alarm and urgency through active-exploitation language and immediate remediation advice.
- alarm loaded criticality and takeover language, reinforced by large blocked-attempt counts, make the issue feel more severe
- urgency an immediate-upgrade instruction and directory-check advice frame the response as time-sensitive