Hackers are actively exploiting a recently patched critical vulnerability in the Elementor Pro WordPress plugin to upload malicious files and execute commands on vulnerable websites.

The flaw, tracked as CVE-2026-32475, affects Elementor Pro versions 4.2.1 and earlier and has already triggered nearly 200,000 blocked exploitation attempts.

Elementor Pro is one of the most widely used WordPress plugins, with more than 6 million active installations. It allows users to build websites through a drag-and-drop editor, making the vulnerability particularly concerning for websites that rely on the plugin.

The vulnerability was patched on August 19, when Elementor released version 4.2.2. However, attackers began exploiting the flaw around the same time the fix was released. Defiant’s Wordfence Web Application Firewall has since blocked more than 190,000 attempts targeting its customers.

The issue is caused by improper validation of file-upload arrays in Elementor Pro forms. Attackers can submit an empty file as the first item in the array followed by a malicious PHP file as the second. This causes the plugin to stop properly validating the remaining files, allowing the PHP payload to bypass the upload restrictions.

The malicious file is saved inside the /wp-content/uploads/elementor/forms/ directory using a randomly generated filename while retaining the attacker’s .php extension. Once uploaded, attackers can directly access the file and use it to execute arbitrary commands on the server.

Exploitation requires a website to have a published Elementor Pro Form widget containing at least one File Upload field. This is a common setup on websites that use Elementor forms to collect documents or other files from visitors.

READ
Dropbox Says Hackers Compromised About 5,000 Accounts

Wordfence reported that exploitation activity increased between August 19 and August 23, with more than 190,000 attacks blocked during that period. The security firm has also identified IP addresses responsible for thousands of attacks, which administrators can use when creating blocklists.

Website administrators using Elementor Pro should update to version 4.2.2 or a newer release immediately. They should also check the /wp-content/uploads/elementor/forms/ directory for unexpected PHP files. Because this directory is intended for uploaded form submissions, finding a PHP file there can be a strong sign that the website has been compromised and requires further cleanup.


Buy ExpressVPN with PayPal or Credit Card

Advertisement