Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress Sites
A critical flaw tracked as CVE-2026-32475 in Elementor Pro, one of the most widely used WordPress page-builder plugins, is now being actively exploited in the wild. Attackers are leveraging the bug to upload webshells, giving them a persistent backdoor to execute arbitrary commands on affected servers.
Elementor Pro powers page design on millions of WordPress sites, making it an attractive target once a serious flaw surfaces. The vulnerability was patched recently, but as is common with WordPress plugin bugs, a working exploit appeared quickly and site owners have been slow to update.
Once attackers gain webshell access, they can pivot to further compromise the hosting environment, inject spam or malware, steal data, or use the site as infrastructure for other attacks.