# Critical Vulnerability in Elementor Pro Plugin Exploited by Hackers

*Published September 7, 2026*
*Source: [https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/](https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/critical-vulnerability-in-elementor-pro-plugin-exploited-by-hackers) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A severe vulnerability in the Elementor Pro WordPress plugin has been actively exploited by hackers, as reported by security firm Defiant. This plugin, a popular choice for building websites with over ten million installations, is compromised due to an arbitrary file upload issue identified as CVE-2026-32475. The vulnerability, with a critical CVSS score of 9.8, affects all versions up to 4.2.1 and was addressed in version 4.2.2 released on August 19.

The flaw occurs during form submissions where the plugin's validation process fails upon encountering an empty upload slot, allowing subsequent files to bypass checks. This loophole enables attackers to upload malicious PHP payloads that can be executed on the server, potentially compromising the entire site. Defiant has already blocked over 190,000 attempts to exploit this vulnerability following the release of the patch.

Site administrators are urged to update their Elementor Pro plugin to the latest version to mitigate this threat. They should also inspect the /wp-content/uploads/elementor/forms/ directory for unexpected PHP files, which could indicate a compromise. Reviewing server logs for unusual requests to /wp-admin/admin-ajax.php is also recommended. With over six million active installations, a significant number of sites may still be vulnerable if not updated promptly.
