A critical vulnerability in Elementor Pro is being actively exploited against WordPress websites, with attackers attempting to upload executable PHP files and gain control of vulnerable sites.
Wordfence said it had blocked more than 190,000 exploit attempts after the flaw was publicly disclosed on 19 August 2026. The issue, tracked as CVE-2026-32475, affects Elementor Pro versions up to and including 4.2.1 and was patched in version 4.2.2.
The risk is serious, but it does not apply to every Elementor Pro website. Exploitation requires a published page using the Elementor Pro Form widget with at least one non-required File Upload field. That makes sites using forms for CV uploads, receipts, photos, support documents or similar attachments the most important to check.
The flaw allows an unauthenticated attacker to bypass file validation and place an executable PHP file in the Elementor forms upload directory. If that file runs successfully, an attacker could execute commands on the server and potentially take over the website.
For UK small businesses, the practical response is straightforward: check the installed Elementor Pro version and update to at least 4.2.2, although using the latest stable release is the safer choice. Elementor’s own changelog shows further Pro releases after the security fix, so an old 4.2.1-or-earlier installation should not be left online.
Businesses should also review any Elementor forms that accept file uploads, check the /wp-content/uploads/elementor/forms/ directory for unexpected PHP files, and look for unfamiliar administrator accounts or other signs of compromise. Updating the plugin closes the vulnerability, but it does not automatically remove malicious files if a site was already breached.
This is also a reminder that routine website maintenance and support is not simply about keeping a site fast or fixing visual bugs. Plugin updates can contain important security fixes, and delays between a patch being released and it being installed can leave a business website exposed.
If a site is already behaving unusually, redirecting visitors, showing unknown admin users or otherwise appears compromised, emergency website fixes may be more appropriate than a routine update.
