The critical Elementor Pro vulnerability WPWithin covered when it was patched two weeks ago is now under active attack. Wordfence says its firewall has blocked more than 190,000 exploit attempts targeting the flaw.

What happened

Elementor Pro, installed on more than 6 million WordPress sites, had a critical unauthenticated file upload flaw tracked as CVE-2026-32475, with a CVSS severity score of 9.8 out of 10. Attackers could exploit it without ever logging in, uploading executable PHP files that lead to remote code execution and full site takeover. The vendor patched the flaw in version 4.2.2 on August 19.

Wordfence, which disclosed the vulnerability the same day, reports that attackers are now actively targeting sites still running the vulnerable version. Its firewall has already blocked over 190,000 exploit attempts.

What to do

If your site runs Elementor Pro, check your version now. Anything at 4.2.1 or earlier is exposed. Update to 4.2.2 or later immediately.

Wordfence users, including those on the free version, get built-in Malicious File Upload protection that blocks exploit attempts against this flaw. That protection buys time, but it’s not a substitute for updating the plugin itself.


End of article