WordPress sites built with Elementor Pro can be compromised by attackers through a vulnerability in the form module. The fix is to update the plugin to version 4.2.2.
A vulnerability identified as CVE-2026-32475, with a severity rating of 9 out of 10, is located in the file upload field of the Elementor Pro form module. Verifying the file extension and moving the file are two separate steps, and an unauthenticated attacker can exploit this to upload a PHP file and execute code on the server—that is, take control of the site. The vulnerability is already being exploited in real-world attacks.
Why this matters for a small business: Many portfolio websites are built using WordPress and Elementor Pro, and at the time of the disclosure, approximately two-thirds of the millions of installations were running a vulnerable version. If the website has a contact form built with Elementor, that’s exactly where the attack vector lies.
A compromised website isn’t just a broken page. It can redirect visitors to scams, expose customer data entered into forms, and undermine the trust you’ve built—not to mention the time and cost of cleaning it up.
What you need to do: Check which version of Elementor Pro your website is running; the fix is in version 4.2.2 or later. If you don't manage the website yourself, ask the person who does to confirm that they've applied the update. If you use Elementor forms, treat this as a priority.
You don't have to be the expert. Just make sure someone clicked "Update" and that the version installed is the fixed one.
Sources:
- BleepingComputer | https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/
- SecurityWeek | https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/
This article was generated with AI assistance.