Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: [incident, wordpress, rce, actively-exploited] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, global-macro] ยท au_impact: true

Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites

Wordfence is reporting active exploitation of a critical flaw in the WordPress Elementor Pro plugin that lets an unauthenticated attacker upload a malicious PHP file to a site and execute arbitrary commands.

Assessment

The vulnerability, CVE-2026-32475, is a critical file-upload-array validation bypass present in Elementor Pro versions 4.2.1 and earlier. It allows an unauthenticated attacker to upload a malicious PHP file to the /wp-content/uploads/elementor/forms/ directory and execute commands, enabling full site takeover via webshell. The exploit only works on sites running a published Elementor Pro Form widget with at least one File Upload field, which is a common configuration given the plugin's installed base of more than 6 million sites.

Exploitation began on 19 August โ€” the same day Elementor shipped version 4.2.2 โ€” with Wordfence attributing the report. Wordfence reports more than 190,000 blocked exploitation attempts between 19 and 23 August, with attackers delivering webshell payloads. The plugin is patched in version 4.2.2; administrators should upgrade immediately and inspect the /wp-content/uploads/elementor/forms/ directory for rogue PHP files.

The threat is directly relevant to Australian businesses and agencies that operate WordPress sites, with the plugin widely deployed in Australian SMB environments. Site owners should apply the patch to 4.2.2+ without delay, inspect the forms upload directory for unexpected PHP files, and review access logs for signs of webshell activity. Given the scale of blocked attempts and the unauthorised-upload path, this is a high-priority remediation for any exposed site.

Sources: Wordfence via BleepingComputer โ€” https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/