ZeroHour
Story · 1 source · 1 articlefirst updated ()

Elementor Pro file-upload flaw CVE-2026-32475 actively exploited; WordPress.org adds AI-powered automated security review for plugin releases

criticalToolsexploited in the wildimportance 82CVE-2026-32475
What's new: Elementor Pro 4.2.2 (released August 19, 2026) patched CVE-2026-32475; sites running versions up to 4.2.1 remain exposed to active exploitation and should update, check /wp-content/uploads/elementor/forms/ for unexpected PHP files, and review requests to /wp-admin/admin-ajax.php (per Defiant).
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers are actively exploiting CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in the Elementor Pro WordPress plugin patched in version 4.2.2 on August 19; Defiant had blocked more than 190,000 exploit attempts, and roughly…

These reports cover two WordPress security developments. First, Defiant reports active exploitation of CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in Elementor Pro's form submission handling caused by a validation-loop bug. The flaw affects all versions up to 4.2.1 and was fixed in Elementor Pro 4.2.2, released August 19, 2026; exploitation began immediately after the patch shipped, and Defiant had blocked more than 190,000 exploit attempts as of its September 5 advisory. Roughly two-thirds of the plugin's 10 million installations still ran a vulnerable version as of September 4. Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/ and can lead to remote code execution and full site compromise. Second, the WordPress.org Plugins Team has introduced an automated security review that scores each release using multiple AI models plus Jetpack Scan during a six-hour cooldown and automatically blocks releases above a risk threshold from the update API. The six-hour cooldown has held all releases, including one-click dashboard updates, since June 5, 2026; Help Net Security and GBHackers say the automated review launch followed the July 28, 2026 backdoor incident, while Cyber Security News dates the combined cooldown-plus-AI-review process to June 5, 2026. That July 28 backdoor, committed to a release of a plugin with roughly 20,000 active installations, was withheld and the plugin closed for downloads 26 minutes after Wordfence notified the Plugins Team, so it never reached users. Sources disagree on scope: Help Net Security and Cyber Security News say the review covers plugin and theme releases, while GBHackers describes plugin releases only. Blocked authors are notified of findings and can publish a corrected release scoring below the threshold or appeal to the Plugins Team; Help Net Security notes publishing a fix is usually faster, and GBHackers reports authors are advised to publish corrected versions rather than await manual appeal.

  • CVE-2026-32475 (CVSS 9.8): unauthenticated arbitrary file upload in Elementor Pro's form submission handling, caused by a validation-loop bug; affects all versions up to 4.2.1.
  • Fixed in Elementor Pro 4.2.2, released August 19, 2026; exploitation began immediately after the patch shipped.
  • Defiant has blocked more than 190,000 exploit attempts (as of its September 5, 2026 advisory).
  • Roughly two-thirds of Elementor Pro's 10 million installations still ran a vulnerable version as of September 4, 2026.
  • Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/ and can lead to remote code execution and full site compromise; Defiant advises administrators to check that directory for PHP files and…
  • WordPress.org now automatically security-scores every plugin release using multiple AI models plus Jetpack Scan during a six-hour cooldown; releases above the risk threshold are automatically blocked from the WordPress.org update API.
  • The six-hour cooldown has held all releases, including one-click dashboard updates, since June 5, 2026 (Help Net Security; Cyber Security News).
  • Scope disagreement: Help Net Security and Cyber Security News say the review covers plugin and theme releases; GBHackers describes plugin releases only.

Coverage timeline

  1. · 11d ago
    SecurityWeek· 82
    Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

    Attackers are actively exploiting critical file-upload flaw CVE-2026-32475 in Elementor Pro, hacking WordPress sites; Defiant has blocked over 190,000 exploit attempts since patching.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32475
Unauthenticated PHP File Upload (RCE) in Elementor Pro WordPress Plugin

Elementor Pro, the paid add-on to the widely used Elementor page builder for WordPress, is affected by an unrestricted upload of files with dangerous types (CWE-434) that can be triggered by unauthenticated attackers. An attacker sends a crafted upload request to the plugin's vulnerable endpoint and can upload a dangerous file — notably a PHP file — which the web server then executes, yielding remote code execution on the hosting account. The critical 9.0 CVSS score with scope change (S:C) and high impact across confidentiality, integrity and availability reflects that code execution lets an attacker take over the site, plant backdoors, modify content and potentially affect the underlying host. All Elementor Pro releases up to and including 4.2.1 are affected, meaning every site that has not yet updated to a fixed version is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is cataloged, and EPSS assigns a 2.4% 30-day exploitation probability (83rd percentile), but news reports already document hundreds of thousands of exploit attempts against Elementor Pro and Super Forms RCE flaws, so it should be treated as exploited in the wild.

Do: Update Elementor Pro to the latest patched release (any version after 4.2.1 — the data does not name a fixed build, so apply the newest available update). Until then, use WAF rules to block unauthenticated upload attempts to Elementor endpoints, restrict or disable modules that accept file uploads from unauthenticated users, and hunt for unexpected .php files under wp-content/uploads plus new admin users or modified content as signs of compromise. The high attack complexity (AC:H) means not every install may be exploitable, but patching should be treated as urgent given the reported mass exploitation.

9.02%
  • Elementor Pro (WordPress plugin) All versions from n/a through 4.2.1 (i.e., every release up to and including 4.2.1)
mass≈1,000,000+ WordPress sites (Elementor Pro is the paid add-on to a page builder whose free core has 10M+ active installs)