GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress Sites

A newly patched vulnerability in the popular page-builder plugin is being used to drop webshells and run commands on compromised servers.

A critical flaw tracked as CVE-2026-32475 in Elementor Pro, one of the most widely used WordPress page-builder plugins, is now being actively exploited in the wild. Attackers are leveraging the bug to upload webshells, giving them a persistent backdoor to execute arbitrary commands on affected servers.

Elementor Pro powers page design on millions of WordPress sites, making it an attractive target once a serious flaw surfaces. The vulnerability was patched recently, but as is common with WordPress plugin bugs, a working exploit appeared quickly and site owners have been slow to update.

Once attackers gain webshell access, they can pivot to further compromise the hosting environment, inject spam or malware, steal data, or use the site as infrastructure for other attacks.

Why it matters: WordPress's plugin ecosystem is a favorite target precisely because updates often lag far behind disclosure, turning patched bugs into long-running exploitation windows. Site owners and hosts running Elementor Pro should treat this as urgent: update immediately and check for existing webshells rather than assuming the patch alone fixes an already-compromised site.

Sources: BleepingComputer