Code Defence Cyber security

Critical Elementor Pro WordPress plugin vulnerability CVE-2026-32475 actively exploited to drop webshells

Active wild exploitation targeting a highly popular drag and drop website builder plugin has been confirmed across global web application firewall networks. Unauthenticated remote actors submit malformed parameter arrays to bypass file validation filters, writing arbitrary PHP webshells onto hosting servers.

The vulnerability, tracked as CVE-2026-32475 with a CVSS score of 9.8, impacts Elementor Pro versions 4.2.1 and earlier when a published Form widget contains a File Upload field. The flaw stems from faulty validation of file-upload arrays in form submission handlers. By submitting an empty file payload as the first array element paired with a malicious PHP script as the second, attackers force validation logic to halt validation, dropping executable PHP files into /wp-content/uploads/elementor/forms/ paths. Threat monitoring arrays have blocked over 190,000 active exploitation attempts.

Subverting public web publishing plugins provides adversaries with immediate remote code execution rights over web hosting environments. Armed with web shell persistence, attackers can extract local database connection keys, harvest administrator credentials, siphon subscriber information, and deploy secondary malware droppers.

– Force immediate maintenance upgrades across all WordPress sites running Elementor Pro to release version 4.2.2 or higher.

– Inspect the /wp-content/uploads/elementor/forms/ directory for unauthorized PHP files, treating any present script as a indicator of compromise.

– Deploy web application firewall inspection rules to intercept incoming HTTP POST requests containing malformed file array payloads.

– Restrict file execution permissions within media and upload directory paths across web server configurations.

Web application perimeter defense requires rigid input array sanitization and continuous upload directory auditing to ensure public site builder plugins remain protected from unauthenticated file upload exploitation. #CodeDefence #WordPress #ElementorPro #RCE #WebShell #AppSec #PatchManagement #WebSecurity
/

Scroll to Top