Home / Sep 04, 2026 / Story
0
#6 BleepingComputer general September 03, 2026 at 14:52 UTC

Critical Elementor Pro flaw exploited to take over WordPress sites

By Bill Toulas

AI Summary

CVE-2026-32475, a recently patched critical vulnerability in the Elementor Pro WordPress plugin, is being actively exploited to deploy webshells and execute arbitrary server-side commands. Given that Elementor Pro is installed on millions of WordPress sites, the attack surface is substantial. Security teams managing WordPress environments should verify plugin update status and audit for webshell indicators of compromise immediately.

Relevance score: 86.0/100

# More from September 04