
Critical Elementor Pro Vulnerability CVE-2026-32475 Actively Exploited to Takeover WordPress Sites
SecurityWordPressElementorVulnerabilityCVE-2026-32475WebshellExploitPlugin
A recently patched critical vulnerability identified as CVE-2026-32475 in the Elementor Pro plugin for WordPress is being actively exploited in attacks. The exploitation involves attackers delivering a webshell payload to compromised WordPress sites and executing arbitrary commands on the server. The vulnerability has been patched, but sites running vulnerable versions of Elementor Pro are being targeted to achieve complete takeover of WordPress installations.