Elementor Pro Plugin Vulnerability Actively Exploited
A critical vulnerability in the Elementor Pro WordPress plugin is being exploited to upload malicious PHP files, allowing attackers to compromise websites.

Hackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin to take over websites. The flaw allows an unauthenticated attacker to upload arbitrary PHP files to a server, according to a warning from WordPress security firm Defiant.
The vulnerability, tracked as CVE-2026-32475, carries a maximum severity CVSS score of 9.8. It is an arbitrary file upload flaw within the plugin's form submission handling function. Defiant explains that the bug exists in how the plugin validates files uploaded through its Form widget.
How the File Upload Flaw Works
When a form with a file upload field is submitted, the plugin's validation process checks each uploaded file. The vulnerability triggers when the validation loop encounters an upload slot marked as empty. Instead of skipping the empty slot and continuing to validate other files in the same field, the function throws an error and returns, aborting all further validation for that field.
An attacker can exploit this by submitting an upload field as an array containing two parts. The first part is an empty slot designed to trigger the validation error and early return. The second part contains a malicious PHP payload. Because the validation loop aborts, the malicious file is processed and written to disk without any security checks.
"As a result, an unauthenticated attacker can request the uploaded file to execute their PHP payload on the server," Defiant states. This execution can lead to a full site compromise.
Patch and Exploitation Timeline
The security defect impacts all Elementor Pro plugin versions up to and including 4.2.1. The vendor, Elementor, released a patch in version 4.2.2 on August 19. Site administrators are urged to update to this fixed version immediately.
Threat actors began exploiting the vulnerability almost immediately after the patch was made available. Defiant reports that its systems have already blocked more than 190,000 exploit attempts.
| Plugin Status | Version | Date |
|---|---|---|
| Vulnerable Versions | Up to 4.2.1 | - |
| Patched Version | 4.2.2 | August 19 |
Indicators of Compromise and Mitigation
A successful attack results in a PHP file being written to a specific directory on the web server: /wp-content/uploads/elementor/forms/. This directory normally stores legitimate user submissions from Elementor Pro forms, not executable code.
Site owners should check this directory for any PHP files, as their presence is a strong indicator of compromise. Defiant also advises administrators to review server logs for suspicious requests to /wp-admin/admin-ajax.php. If any evidence of exploitation is found, a thorough investigation for backdoors and other malware is necessary.
Elementor Pro has over 6 million active installations. Data from WordPress suggests that as of September 4, roughly two-thirds of the broader Elementor ecosystem's 10 million installations were running a vulnerable plugin version. The exact number of affected Elementor Pro sites remains unclear.
Defiant continues to monitor the exploitation campaign and block attack attempts.





