Elementor Pro CVE-2026-32475: patching doesn't remove the webshell
Elementor shipped a fix for CVE-2026-32475 on August 19, but attackers began exploiting it the same day and Wordfence blocked over 190,000 attempts in five days. The flaw lets an unauthenticated attacker drop a PHP file into wp-content/uploads/elementor/forms/ and execute it, so updating the plugin does not remove a webshell already planted on the site.
- Wordfence blocked more than 190,000 exploitation attempts in the first five days
- Elementor Pro 4.2.1 and earlier are affected, with 6M+ active installs
- Exploit is a single unauthenticated POST to admin-ajax.php with no nonce
- Patching closes the vulnerability but does not remove an existing webshell
Read next
Security