Affected Systems
Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.
Exploitation Status
Active exploitation confirmed since August 19, 2026. Wordfence blocked 190,000+ exploitation attempts between August 19-23. Attackers uploading PHP webshells to /wp-content/uploads/elementor/forms/ for remote command execution.
Business Impact
Attackers gain arbitrary command execution on WordPress servers by exploiting file upload validation bypass. Successful exploitation allows full server compromise via webshell deployment. High-value target due to 6 million+ installations. Exploitation requires published form with file upload field (common configuration). Patch available since August 19 (version 4.2.2).
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade Elementor Pro to version 4.2.2 or later on all WordPress installations
- Inspect /wp-content/uploads/elementor/forms/ directory for any .php files; legitimate form uploads should not contain PHP files
- Review web server access logs for POST requests to /wp-content/uploads/elementor/forms/*.php since August 19, 2026
- Block known malicious IP addresses published by Wordfence in firewall rules
- If compromise detected, perform full incident response including credential rotation, malware scan, and integrity verification of WordPress core and plugin files
