Wire · opportunities
Critical vulnerability in Elementor Pro exploited for RCE attacks
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 4 September 2026 · Fusion42 review
A critical vulnerability (CVE-2026-32475) in Elementor Pro versions 4.2.1 and earlier is actively exploited to upload malicious PHP webshells allowing remote code execution on affected WordPress sites. Users are urged to update to version 4.2.2 and scan for compromises as over 6 million active sites are at risk.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
You must update Elementor Pro immediately or your WordPress site could be commandeered via webshell. This flaw opens up a direct route for attackers to your server — patch now and check for hidden file uploads.
◆ Coverage
1 source · 4 Sep 2026
◆ Related on Wire
◆ Topics