Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Refract AI Intelligence Digest
BLUF
Critical Elementor Pro file upload bug is actively exploited; patch immediately.
NEWS
CVE-2026-32475 allows arbitrary file uploads via form submissions with a CVSS score of 9.8. Attackers are already using this flaw to hack sites running unpatched versions of the plugin.
Why I Care
Unpatched WordPress sites using Elementor Pro face immediate risk of full compromise, data theft, or malware installation due to active exploitation.
Next Steps
Update Elementor Pro to the latest version immediately and audit server logs for suspicious file uploads or changes.
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
Source: Security Week ·