Critical Elementor Pro Flaw Actively Exploited to Upload PHP Web Shells on WordPress Sites
A critical vulnerability in Elementor Pro versions 4.2.1 and earlier, tracked as CVE-2026-32475, is being actively exploited to upload malicious PHP web shells to WordPress sites. The flaw resides in the plugin's file upload validation logic, where submitting a File Upload field as an array with an empty first element causes extension and file type checks to be bypassed entirely. Unauthenticated attackers can exploit this on any public form containing a non-mandatory File Upload field, with successful uploads landing PHP files in the wp-content/uploads/elementor/forms/ directory. Security firm Wordfence reported blocking over 190,000 attack attempts, though this figure reflects blocked requests and not confirmed site compromises. Site owners are advised to update immediately to version 4.2.2 or later and to disable PHP execution in upload directories as an additional safeguard.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in