Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.5

Elementor Pro CVE-2026-32475 exploited in WordPress site takeovers

A critical, recently patched vulnerability in Elementor Pro (CVE-2026-32475) is under active exploitation, with attackers deploying webshells and executing arbitrary commands on affected WordPress servers. The flaw was patched but unpatched sites remain at risk; the scale of compromise is unclear. This matters because Elementor Pro is widely used, making this a high-impact supply-chain style threat to a large install base.

BleepingComputer2 days agoengCredibility 54%View source

Score Breakdown

Mosaic Score7.5
Confidence0.7
Significance0.8
Source credibility0.5
Source

Related signals

7 found