A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
Elementor Pro is a popular WordPress plugin with more than 6 million active installations, allowing users to build websites using a drag-and-drop interface.
The CVE-2026-32475 vulnerability was patched on August 19. Since then, Defiant's Wordfence web application firewall has blocked almost 200,000 exploitation attempts targeting its clients.
The issue stems from faulty validation of file-upload arrays in Elementor Pro forms and is present in versions 4.2.1 and earlier.
By submitting an empty file as the first array element and a malicious PHP file as the second, attackers can cause the plugin to stop validating subsequent files.











