Critical Elementor Pro flaw exploited to take over WordPress sites

Summary

A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin is actively being exploited to gain administrative access and execute arbitrary commands on affected websites. Attackers are deploying webshells to maintain persistence and control over compromised sites.

IFF Assessment

FOE

The active exploitation of a critical vulnerability in a widely used WordPress plugin poses a significant threat to website owners and defenders.

Severity

9.0 Critical

Defender Context

Defenders should prioritize patching the Elementor Pro plugin immediately if they use it. Monitoring for unusual file activity and unauthorized webshells on WordPress sites is crucial to detect and respond to ongoing exploitation attempts.

Read Full Story →