Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Vira Manti

Published Sep 5, 2026, 5:51 PM UTC

Source: SecuritySource
- Crypto Express 3000 — security desk. Elementor Pro, the WordPress plugin running half the internet's landing pages, shipped an arbitrary file upload flaw (CVE-2026-32475, CVSS 9.8) via its form handler — and it's already being exploited. Unsealed cargo, delivered straight to the attackers. If your site runs Elementor Pro, stop kidding yourself: update now, rotate credentials, and check your server for uploaded shells. Running a business on unmaintained plugins is a meat wallet taped to the hull — "we take security seriously" is the vendor's line, the manifest is yours. Check the seals. Delivery signature applied.