A critical security vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload web shells and execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-32475, the flaw affects Elementor Pro versions 4.2.1 and earlier.
Elementor Pro is one of the most widely used WordPress plugins, with more than 6 million active installations. The page builder enables website owners to create pages and forms using a drag-and-drop interface.
Elementor addressed the vulnerability on August 19 by releasing version 4.2.2. Since then, Defiant’s Wordfence Web Application Firewall has blocked approximately 200,000 exploitation attempts targeting protected WordPress websites.
The Elementor Pro vulnerability is caused by improper validation of file upload arrays in Elementor forms. Attackers can submit an empty file as the first array element, followed by a malicious PHP file as the second element. This causes the plugin to stop validating the remaining files, allowing the PHP payload to bypass security checks.
Uploaded files are saved in the /wp-content/uploads/elementor/forms/ directory. If a malicious PHP file is uploaded successfully, attackers can access it directly and execute arbitrary commands on the WordPress server.
WordPress security platform Patchstack warned last month that CVE-2026-32475 could allow unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution on affected servers.
Successful exploitation requires a published Elementor Pro Form widget containing at least one file upload field, a configuration commonly used on WordPress websites.
Wordfence reported that exploitation began on August 19, the same day Elementor released version 4.2.2. The security company observed the highest level of activity between August 19 and August 23, blocking more than 190,000 attack attempts.
“The attacker submits the form’s file upload field as an array. The first element is empty and the second element contains a PHP payload with a .php filename. This is the structure that triggers the validation bypass,” Wordfence said.

Source: Wordfence
“Once created, the uploaded PHP file is placed in the /wp-content/uploads/elementor/forms/ directory with a randomly generated filename with a .php extension specified by the attacker, allowing the attacker to directly request execution of arbitrary commands on the server,” the security firm explained.
Wordfence has also published a list of IP addresses associated with thousands of exploitation attempts. Administrators can use the list as an additional resource when reviewing firewall logs and creating block rules.
WordPress administrators should immediately update Elementor Pro to version 4.2.2 or later. After updating, website owners should inspect the /wp-content/uploads/elementor/forms/ directory for unexpected PHP files and investigate any suspicious activity.
This directory is normally used to store uploaded Elementor form submissions. Because PHP files should not typically be present there, finding unexpected .php files may indicate a compromise and should trigger a thorough malware investigation and cleanup process.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



