CVE-2026-32475critical
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.