#6
BleepingComputer
general
September 03, 2026 at 14:52 UTC
Critical Elementor Pro flaw exploited to take over WordPress sites
By Bill Toulas
AI Summary
CVE-2026-32475, a recently patched critical vulnerability in the Elementor Pro WordPress plugin, is being actively exploited to deploy webshells and execute arbitrary server-side commands. Given that Elementor Pro is installed on millions of WordPress sites, the attack surface is substantial. Security teams managing WordPress environments should verify plugin update status and audit for webshell indicators of compromise immediately.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →