Critical Elementor Pro Vulnerability Exploited in the Wild
CVE-2026-32475 allows unauthenticated remote code execution on WordPress sites

Key Takeaways
- CVE-2026-32475 is a critical flaw in the Elementor Pro plugin for WordPress.
- Active exploitation in the wild delivers webshell payloads and enables remote code execution.
- Unauthenticated attackers can take over affected WordPress sites.
- Elementor has released a patch; users must update to the latest plugin version immediately.
- Websites running unpatched Elementor Pro are at risk of full compromise.
Quick answers
- What happened?
- A critical vulnerability in the Elementor Pro plugin for WordPress, tracked as CVE-2026-32475, is being actively exploited in attacks that deliver webshell payloads and enable arbitrary command execution. Elementor has released a patch; users are urged to update immediately.
- Which products are affected?
- Elementor Pro plugin
- What should defenders do?
- Update the Elementor Pro plugin to the latest patched version immediately. Monitor WordPress sites for unusual activity, such as unexpected file creation or webshell artifacts. Apply web application firewall rules to block known exploitation patterns. Regularly audit plugin versions and maintain updated backups.
- Which vulnerabilities are involved?
- CVE-2026-32475
A critical vulnerability in the Elementor Pro plugin for WordPress, tracked as CVE-2026-32475, is being actively exploited in the wild. According to reports, the flaw allows unauthenticated attackers to achieve remote code execution (RCE), take over WordPress sites, and install webshells for persistent access. Exploitation has been observed delivering webshell payloads that enable arbitrary command execution on affected servers. Elementor has released a patched version of the plugin; users are strongly advised to update to the latest version to mitigate the risk. The vulnerability affects WordPress websites using the Elementor Pro plugin globally. While the exact technical vector details remain under investigation, the impact is assessed as critical due to the potential for full site compromise.
Security Details
The vulnerability tracked as CVE-2026-32475 affects the Elementor Pro plugin for WordPress. Active exploitation has been observed delivering webshell payloads that allow unauthenticated attackers to execute arbitrary commands on the server. Elementor has released a patched version; users should update immediately to mitigate the risk of remote code execution and site takeover.
Affected products
Elementor Pro plugin
Mitigation
Update the Elementor Pro plugin to the latest patched version immediately. Monitor WordPress sites for unusual activity, such as unexpected file creation or webshell artifacts. Apply web application firewall rules to block known exploitation patterns. Regularly audit plugin versions and maintain updated backups.
Sources
BleepingComputer
Critical Elementor Pro flaw exploited to take over WordPress sites
Sep 3, 2026 · 14:52
Original link
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


