ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Elementor Pro flaw exploited against WordPress sites

Elementor Pro for WordPress was patched on 19 August, but Wordfence said attackers began using the flaw the same day and had triggered nearly 200,000 blocked attempts.

BleepingComputer

Elementor Pro for WordPress contained CVE-2026-32475 in versions 4.2.1 and earlier. Elementor patched the issue on 19 August in version 4.2.2.

The vulnerability was in validation for file uploads submitted through forms. The article said an attacker could send an empty first array item and a malicious PHP file as the second, which stopped later files from being checked.

Wordfence, which Defiant runs, said it had blocked almost 200,000 exploitation attempts against its customers. It said the activity began on 19 August and ran through 23 August.

Patchstack warned last month that the flaw could let attackers upload arbitrary PHP files and execute code on the server. Administrators were told to upgrade to Elementor Pro 4.2.2 or later and inspect /wp-content/uploads/elementor/forms/ for suspicious PHP files.

Named in this story

Companies

Elementor
released version 4.2.2 that fixed the issue
Defiant
runs Wordfence and said it blocked the attacks
Patchstack
warned that the flaw could let attackers upload PHP files and run code

Products and systems

Elementor Pro
the WordPress plugin containing the flaw
WordPress
the platform the plugin runs on
Wordfence
the firewall that blocked exploitation attempts and reported the activity

How the source tells it

The source was mainly a technical advisory, but it leaned into alarm and urgency through active-exploitation language and immediate remediation advice.

  • alarm loaded criticality and takeover language, reinforced by large blocked-attempt counts, make the issue feel more severe
  • urgency an immediate-upgrade instruction and directory-check advice frame the response as time-sensitive