Overview
- Elementor released a patch for CVE-2026-32475 on August 19, 2026, but security vendors reported attackers began exploiting the flaw the same day.
- The bug lets an attacker submit a file-upload array where an empty first element skips validation and a second element with a .php filename is written to wp-content/uploads/elementor/forms/ and executed as a webshell.
- Wordfence and other vendors have blocked large volumes of activity with more than 190,000 Elementor-directed attempts and over 250,000 attempts against a related Super Forms flaw for a combined total above 440,000.
- Defenders should immediately upgrade to Elementor Pro 4.2.2 or later, scan uploads directories for unexpected .php files, and add webserver rules or WAF rules to deny PHP execution in upload paths.
- Security firms warn this attack follows a recurring validation-versus-move coding pattern seen in other plugins and say site owners should review published pages that include File Upload fields because millions of installations make many sites reachable.