Attackers are actively exploiting CVE-2026-32475, a critical unauthenticated arbitrary-file-upload vulnerability (CVSS 9.8) in Elementor Website Builder Pro for WordPress. The flaw affects versions through 4.2.1 and lets attackers bypass file-extension and type validation in published Elementor Pro Form widgets with non-required File Upload fields, upload PHP webshells, execute arbitrary commands, and potentially fully compromise affected sites.
The vulnerability was fixed in Elementor Pro 4.2.2. Wordfence reported blocking more than 190,000 exploitation attempts shortly after public disclosure; administrators should update immediately and investigate Elementor form-upload directories for unauthorized PHP files, which are a key indicator of compromise.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
As of September 4, WordPress data indicated that approximately two-thirds of Elementor's 10 million installations were running an Elementor Pro version vulnerable to CVE-2026-32475, highlighting the continued exposure following active exploitation.
Wordfence observed attackers actively exploiting CVE-2026-32475 beginning on the public-disclosure date. Exploitation can upload PHP webshells through vulnerable Elementor Pro form-upload fields and enable remote command execution.
Elementor released Elementor Pro 4.2.2, fixing the critical unauthenticated arbitrary file-upload vulnerability CVE-2026-32475 affecting versions 4.2.1 and earlier.
The exploitation campaign targeting CVE-2026-14894 generated more than 40,000 requests in a single day, indicating a significant spike in attacks against vulnerable Super Forms installations.
During heightened exploitation activity from August 19 through August 23, Wordfence blocked more than 190,000 attempts targeting CVE-2026-32475 against its clients.
Attackers began exploiting CVE-2026-14894, a critical unauthenticated arbitrary-file-upload vulnerability in Super Forms, to upload PHP web shells and gain remote code execution on vulnerable WordPress sites. Wordfence blocked more than 250,000 exploit attempts targeting the flaw; Super Forms fixed it in version 6.3.314.
Technical reporting detailed the Super Forms admin-ajax.php exploitation method, including a Base64-encoded PHP payload disguised as image data and the Mushr00w_upl.php upload web shell. It also described Elementor Pro's array-based file-validation bypass, the resulting upload directory, prerequisite Form widget configuration, and source IP indicators for both campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourcescworld.com
Open sourcesocradar.io
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcepatchstack.com
Open sourcewordfence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.