Attackers exploit patched Elementor Pro flaw to plant webshells on WordPress sites
Hackers are actively exploiting CVE-2026-32475, a critical vulnerability in Elementor Pro affecting version 4.2.1 and earlier, by abusing a file-upload validation flaw in the plugin's form widget to upload malicious PHP files and run commands on compromised servers. Elementor patched the bug on August 19 with version 4.2.2, but Wordfence says exploitation began the same day and has already blocked nearly 200,000 attack attempts.