Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Read at SecurityWeekShort publisher excerpt
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
Threat Field Notes · why it matters
Defenders should first confirm whether the affected technology exists in their environment, then prioritize exposed and high-value systems. Treat reported exploitation as a prompt to review telemetry and vendor guidance—not only as a patching reminder.