ZeroHour

Search: “Elementor”

13 stories

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Attackers are actively exploiting critical file-upload flaw CVE-2026-32475 in Elementor Pro, hacking WordPress sites; Defiant has blocked over 190,000 exploit attempts since patching.

Defiant warns that attackers are exploiting CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in the Elementor Pro WordPress plugin's form submission handling, which affects all versions up to 4.2.1 and was patched in version 4.2.2 on August 19. Exploitation began immediately after the fix shipped, with Defiant blocking over 190,000 exploit attempts to date; roughly two-thirds of Elementor's 10 million installations still ran a vulnerable version as of September 4. Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/ and can lead to full site compromise; administrators should check that directory for PHP files and review requests to /wp-admin/admin-ajax.php.

SecurityWeek · 11d agoExploit / PoC in the wildCVE-2026-32475

Elementor Pro RCE Flaw Under Active Attack

A critical Elementor Pro Forms module flaw allowing unauthenticated file uploads is under active attack against widely used WordPress sites.

A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload arbitrary files through the plugin's Forms module. The SOCRadar report indicates the flaw is being actively exploited in the wild. No CVE identifier was provided in the available text.

SOCRadar · 12d agoExploit / PoC in the wild

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

Attackers actively exploit a critical unauthenticated file upload flaw in Elementor Pro (6M+ installs), enabling remote code execution and site takeover.

Wordfence reports that attackers are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in Elementor Pro, which it disclosed on August 19, 2026. The WordPress plugin has more than 6,000,000 active installations. Unauthenticated attackers can upload arbitrary files, including executable PHP files, leading to remote code execution and complete site takeover.

Wordfence · 14d agoExploit / PoC in the wild

N-able Patches Critical Zero-Day in N-central

N-able patches critical unauthenticated RCE zero-day CVE-2026-86218 in N-central, exploited in the wild; on-premises admins must apply hotfix 2026.3 HF4.

N-able released an urgent hotfix (2026.3 HF4) for CVE-2026-86218 (CVSS 10), an unauthenticated RCE in N-central exploited as a zero-day. Scanning/exploitation attempts observed from IP range 23.234.64.0/18 starting September 4; admins should check logs for scanning and unrecognized new accounts. The hotfix supersedes patches for CVE-2026-86206 and CVE-2026-86207, which Huntress observed potentially chained in the wild to bypass authentication in production environments.