Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ‘Sinn Féin traitors!’: how far-right rhetoric derailed party’s path to power in Ireland | Ireland

    September 5, 2026

    Google’s Gemini Spark can now manage your Google Photos library

    September 5, 2026

    Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

    September 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘Sinn Féin traitors!’: how far-right rhetoric derailed party’s path to power in Ireland | Ireland
    • Google’s Gemini Spark can now manage your Google Photos library
    • Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
    • Solana v1 can halt RPC readers and break fee caps
    • Dark matter detector finds a strange signal scientists can’t yet explain
    • Did Trump sign executive order changing name of New Mexico to ‘New America’? Here’s the truth
    • US ambassador to Israel visits Palestinian town hit by West Bank settler violence
    • Reform continues to cast doubt on climate science. Do its supporters agree? | Reform UK
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 5, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns.

    A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for File Upload fields.

    The bug, tracked as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue in the function that handles form submissions.

    While submissions are passed through the plugin’s validation and processing mechanisms, when the validation loop encounters an upload slot marked as empty, it triggers an error and returns, aborting the validation of other files in the field.

    The normal behavior would be to continue, skipping the empty entry, but the vulnerability results in checks never being applied to the remaining files uploaded through the same form field.

    An attacker can submit an upload field as an array with two parts: an empty slot that triggers the return, followed by a PHP payload that is uploaded without validation.

    Advertisement. Scroll to continue reading.

    Because the function that handles field processing correctly skips the empty slot and processes the second, unvalidated part of the field, the attacker-supplied file is written to disk.

    “As a result, an unauthenticated attacker can request the uploaded file to execute their PHP payload on the server,” Defiant explains, noting that this could lead to full site compromise.

    CVE-2026-32475 impacts all Elementor Pro plugin versions up to 4.2.1 and was patched in version 4.2.2 on August 19. Site owners should update to the fixed iteration as soon as possible.

    According to Defiant, threat actors started exploiting the security defect immediately after the fixes landed. The security firm has blocked over 190,000 exploit attempts to date.

    Successful exploitation of the vulnerability results in a PHP file being written to the /wp-content/uploads/elementor/forms/ directory, which stores uploaded form submissions.

    Site administrators are advised to check the directory for the presence of any PHP file, which is a strong indicator of compromise (IoC). They should also check logs for requests to /wp-admin/admin-ajax.php and check their sites for backdoors if any evidence of compromise is discovered.

    Defiant notes that Elementor Pro has over 6 million active installations, but it is unclear how many of them are affected. According to WordPress data, approximately two-thirds of Elementor’s 10 million installations run a vulnerable plugin version as of September 4.

    Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

    Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability

    Related: Google Patches 6th Chrome Zero-Day of 2026

    Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

    Elementor Exploited hack Plugin Pro sites Vulnerability WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI admits it didn’t disclose rogue AI wiki hijacking incident

    Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

    VMware Workstation and Fusion Updates Patch Critical Vulnerability

    Catch Raises $5 Million for AI Executive Assistant With Guardrails

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ‘Sinn Féin traitors!’: how far-right rhetoric derailed party’s path to power in Ireland | Ireland

    September 5, 2026

    Google’s Gemini Spark can now manage your Google Photos library

    September 5, 2026

    Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

    September 5, 2026

    Solana v1 can halt RPC readers and break fee caps

    September 5, 2026
    Latest Posts

    The protein craze may not be for everyone

    July 31, 2026

    Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft

    July 31, 2026

    Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ‘Sinn Féin traitors!’: how far-right rhetoric derailed party’s path to power in Ireland | Ireland

    September 5, 2026

    Google’s Gemini Spark can now manage your Google Photos library

    September 5, 2026

    Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

    September 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.