Elementor Pro vulnerability is actively exploited—update the WordPress plugin
CVE-2026-32475 in Elementor Pro allows unauthenticated users to upload arbitrary files through a publicly accessible form with a File Upload field. A fix is available in version 4.2.2.

The Elementor Pro vulnerability identified as CVE-2026-32475 is reportedly being actively exploited against WordPress sites. The issue affects Elementor Pro versions 4.2.1 and older and is fixed in version 4.2.2, released by Elementor on August 19, 2026.
The flaw is located in the Forms module, specifically in the handling of the File Upload field. Under certain circumstances, an unauthenticated attacker can upload an arbitrary file. If the attacker manages to place and execute a PHP file on the server, this could lead to remote command execution and takeover of the compromised site.
The Elementor Pro vulnerability has a CVSS score of 9.0
Security firm Patchstack rates CVE-2026-32475 with a CVSS score of 9.0. It is therefore not the 9.8 score that appeared in some reports. Patchstack has also published a temporary mitigation rule for cases where an administrator cannot deploy the update immediately.
For the exploit to succeed, a publicly accessible Elementor Pro form with a File Upload field must be available on the site. It is not known how many installations use this configuration. The risk therefore does not automatically affect every site with Elementor Pro, but publicly accessible, unpatched forms with file uploads require immediate review.
Attacks have been recorded since August 19
According to a secondary report, Wordfence recorded exploitation attempts beginning August 19. Wordfence said it blocked nearly 200,000 attempts.
However, this figure covers only Wordfence customers and cannot determine the total scope of attacks on the internet. Neither the number of successfully compromised sites nor the attackers’ identities have been independently confirmed.
What site administrators should do
- Update Elementor Pro to version 4.2.2 or later.
- Check whether the site operates publicly accessible forms with a File Upload field.
- If an update is not immediately possible, restrict or temporarily disable the risky form and deploy the available WAF mitigation.
- Check the site for unknown PHP files or other signs of an uploaded webshell.
In the coming period, it will be important to monitor new indicators of compromise, any potential addition of CVE-2026-32475 to the CISA Known Exploited Vulnerabilities catalog, and whether Elementor publishes a separate security notice with technical details about the fix.
Sources
- Patchstack advisory – Confirms the CVE, affected versions through 4.2.1, the fix in version 4.2.2, the unauthenticated nature of the flaw, CVSS 9.0, and the available mitigation.
- Elementor Pro Changelog – Confirms the release of Elementor Pro 4.2.2 on August 19, 2026, and the security fix in the Form widget.
- BleepingComputer – Corroborates Wordfence’s report of active exploitation, webshells, and nearly 200,000 blocked attempts.
- SecurityWeek – Confirms that active exploitation of the vulnerability is a current security story.
Verified and updated: 09/05/2026 15:20



