Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Summary

A critical arbitrary file upload vulnerability, tracked as CVE-2026-32475, has been discovered and exploited in the Elementor Pro WordPress plugin. This vulnerability, with a CVSS score of 9.8, allows attackers to compromise websites through malicious form submissions.

IFF Assessment

FOE

The exploitation of a critical vulnerability in a widely used WordPress plugin represents a significant threat to website security and user data.

Severity

9.0 Critical

Defender Context

Website administrators using Elementor Pro should immediately update to the patched version to mitigate the risk of exploitation. This incident highlights the ongoing threat posed by vulnerabilities in popular CMS plugins and the importance of regular patching.

Read Full Story →