Home / Sep 06, 2026 / Story
0
#9 SecurityWeek general September 05, 2026 at 13:00 UTC

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

By Ionut Arghire

AI Summary

CVE-2026-32475 (CVSS 9.8), a critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin's form submission handler, is being actively exploited to compromise websites. Given Elementor Pro's widespread deployment across WordPress sites, administrators should apply patches immediately.

Relevance score: 76.0/100

# More from September 06