ZeroHour
Story · 1 source · 1 articlefirst updated ()

Actively Exploited Elementor Pro File-Upload Flaw (CVE-2026-32475); WordPress.org Adds AI-Powered Security Review for Plugin Releases

criticalToolsexploited in the wildimportance 82CVE-2026-32475
What's new: No previous merged summary exists (this is the first merge for this story). Changes covered in this window: Elementor Pro 4.2.2 (August 19, 2026) fixed the actively exploited CVE-2026-32475, with exploitation starting immediately after the patch and Defiant's blocked-attempt count reaching 190,000+ by September 5; roughly two-thirds of ~10 million installs were still unpatched as of September 4.…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers are actively exploiting CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in the Elementor Pro WordPress plugin's Forms module, fixed in version 4.2.2 on August 19; Defiant has blocked more than 190,000 exploit attempts.…

Defiant (reported by SecurityWeek) and SOCRadar warn that a critical, actively exploited vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allows unauthenticated attackers to upload arbitrary files through the plugin's form submission handling (Forms module), caused by a validation-loop bug. The flaw, tracked as CVE-2026-32475 with CVSS 9.8, affects all versions up to 4.2.1 and was patched in Elementor Pro 4.2.2, released August 19, 2026. SOCRadar's earlier report did not include a CVE identifier; SecurityWeek identifies it as CVE-2026-32475. Exploitation began immediately after the patch shipped: Defiant has blocked over 190,000 exploit attempts, and roughly two-thirds of the plugin's approximately 10 million installations still ran a vulnerable version as of September 4. Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/, enabling remote code execution and full site compromise; administrators are advised to check that directory for PHP files and review requests to /wp-admin/admin-ajax.php. In related WordPress supply-chain news, the WordPress Official Plugin Repository Team has launched an automated security review: since June 5, 2026, every plugin release (Help Net Security and Cyber Security News also describe theme releases as covered) is held in a six-hour cooldown while multiple AI models and Jetpack Scan analyze code changes and produce a consolidated risk score; releases above the blocking threshold are automatically held back from the WordPress.org update API. The change followed a July 28, 2026 incident in which a backdoor was committed to a release of a plugin with roughly 20,000 active installations; Wordfence notified the team and the compromised release/plugin was pulled 26 minutes later, never reaching users (Help Net Security describes the release as withheld and the plugin closed for downloads). Blocked authors are notified of the findings and can publish a corrected release scoring below the threshold, which is usually faster, or appeal to the Plugins Team; per Cyber Security News, scores measure risk exposure rather than developer intent, and false-positive reports are requested.

  • CVE-2026-32475 (CVSS 9.8): unauthenticated arbitrary file upload in Elementor Pro form submission handling, caused by a validation-loop bug (SecurityWeek/Defiant); SOCRadar's earlier report described the same flaw without a CVE identifier.
  • Affects all Elementor Pro versions up to 4.2.1; fixed in Elementor Pro 4.2.2, released August 19, 2026.
  • Exploitation began immediately after the August 19 patch shipped; Defiant has blocked more than 190,000 exploit attempts as of the September 5 report.
  • Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/, enabling remote code execution and full site compromise.
  • Roughly two-thirds of Elementor Pro's approximately 10 million installations remained vulnerable as of September 4, 2026.
  • Defiant advises administrators to check /wp-content/uploads/elementor/forms/ for PHP files and review requests to /wp-admin/admin-ajax.php.
  • Since June 5, 2026, every WordPress.org plugin release (two reports also include theme releases) passes an automated security review: a six-hour cooldown, analysis by multiple AI models plus Jetpack Scan, and a consolidated risk score;…
  • Trigger incident: a July 28, 2026 backdoor committed to a release of a plugin with roughly 20,000 active installations; Wordfence notified the team, and the compromised release/plugin was pulled 26 minutes later without reaching users.

Coverage timeline

  1. · 12d ago
    SOCRadar· 78
    Elementor Pro RCE Flaw Under Active Attack

    A critical Elementor Pro Forms module flaw allowing unauthenticated file uploads is under active attack against widely used WordPress sites.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32475
Unauthenticated PHP File Upload (RCE) in Elementor Pro WordPress Plugin

Elementor Pro, the paid add-on to the widely used Elementor page builder for WordPress, is affected by an unrestricted upload of files with dangerous types (CWE-434) that can be triggered by unauthenticated attackers. An attacker sends a crafted upload request to the plugin's vulnerable endpoint and can upload a dangerous file — notably a PHP file — which the web server then executes, yielding remote code execution on the hosting account. The critical 9.0 CVSS score with scope change (S:C) and high impact across confidentiality, integrity and availability reflects that code execution lets an attacker take over the site, plant backdoors, modify content and potentially affect the underlying host. All Elementor Pro releases up to and including 4.2.1 are affected, meaning every site that has not yet updated to a fixed version is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is cataloged, and EPSS assigns a 2.4% 30-day exploitation probability (83rd percentile), but news reports already document hundreds of thousands of exploit attempts against Elementor Pro and Super Forms RCE flaws, so it should be treated as exploited in the wild.

Do: Update Elementor Pro to the latest patched release (any version after 4.2.1 — the data does not name a fixed build, so apply the newest available update). Until then, use WAF rules to block unauthenticated upload attempts to Elementor endpoints, restrict or disable modules that accept file uploads from unauthenticated users, and hunt for unexpected .php files under wp-content/uploads plus new admin users or modified content as signs of compromise. The high attack complexity (AC:H) means not every install may be exploitable, but patching should be treated as urgent given the reported mass exploitation.

9.02%
  • Elementor Pro (WordPress plugin) All versions from n/a through 4.2.1 (i.e., every release up to and including 4.2.1)
mass≈1,000,000+ WordPress sites (Elementor Pro is the paid add-on to a page builder whose free core has 10M+ active installs)