Hackers are exploiting a critical vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant has warned.
A hugely popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installs. Elementor Pro is the paid version that offers additional features, including an executable form module with file upload field support.
The error traced as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue in the function that handles form submissions.
As submissions are passed through the plugin’s validation and processing mechanisms, when the validation loop encounters an upload slot marked as empty, it raises an error and returns, breaking the validation of other files in the field.
The normal behavior would be to proceed by skipping the empty entry, but the vulnerability causes checks to never be applied to other files uploaded through the same form field.
An attacker can send an upload field as a two-part array: an empty slot that triggers the return, followed by a PHP payload that is uploaded without validation.
Because the function that correctly handles field processing skips the empty slot and processes the second, unchecked part of the field, the attacker’s supplied file is written to disk.
“As a result, an unauthorized attacker could request the uploaded file to execute their PHP payload on the server,” Defiant explainsnoting that this could lead to a complete compromise of the site.
CVE-2026-32475 affects all versions of the Elementor Pro plugin up to 4.2.1 and was fixed in version 4.2.2 on August 19. Site owners should update to the fixed iteration as soon as possible.
According to Defiant, threat actors began to exploit the security flaw as soon as the patches landed. The security firm has blocked over 190,000 usage attempts to date.
Successful exploitation of the vulnerability causes a PHP file to be written to the /wp-content/uploads/elementor/forms/ directory that stores uploaded form submissions.
Site administrators are advised to check the directory for the presence of a PHP file, which is a strong indicator of compromise (IoC). They should also check logs for requests to /wp-admin/admin-ajax.php and check their sites for backdoors if evidence of compromise is found.
Defiant notes that Elementor Pro has over 6 million active installs, but it’s unclear how many of those are affected. According to WordPress dataapproximately two-thirds of Elementor’s 10 million installations were running a vulnerable version of the plugin as of September 4.
Related: 12-year-old PostgreSQL vulnerability allows database and server takeover
Related: VMware Workstation and Fusion updates fix critical vulnerability
Related: Google Patches 6th Chrome Zero-Day of 2026
Related: Over 3 million WordPress sites affected by migration plugin vulnerability