Elementor Pro Exploitation Turns Plugins Into Shells

BleepingComputer says attackers are exploiting a critical Elementor Pro flaw, CVE-2026-32475, to break into WordPress sites and plant webshells that let them run arbitrary commands on the server. The issue is already past disclosure and into hands-on compromise. A webshell is a small backdoor dropped on the server and reached through a browser, so the attacker does not need to re-use the original plugin bug every time. Once it is in place, the compromise can persist after the plugin is updated, and the server itself can be used for further abuse. For WordPress operators using Elementor Pro, the exposure sits at the server layer, not just inside the plugin. If the site has already been hit, updating alone does not describe the full cleanup story because the attacker’s command channel may still be present.

Part of the PlainSec briefing for 2026-09-03

Editions

Sources