Critical Elementor Pro flaw exploited to take over WordPress sites
Summary
A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin is actively being exploited to gain administrative access and execute arbitrary commands on affected websites. Attackers are deploying webshells to maintain persistence and control over compromised sites.
IFF Assessment
FOE
The active exploitation of a critical vulnerability in a widely used WordPress plugin poses a significant threat to website owners and defenders.
Severity
9.0
Critical
Defender Context
Defenders should prioritize patching the Elementor Pro plugin immediately if they use it. Monitoring for unusual file activity and unauthorized webshells on WordPress sites is crucial to detect and respond to ongoing exploitation attempts.