Affected Systems

Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.

Exploitation Status

Active exploitation confirmed since August 19, 2026. Wordfence blocked 190,000+ exploitation attempts between August 19-23. Attackers uploading PHP webshells to /wp-content/uploads/elementor/forms/ for remote command execution.

Business Impact

Attackers gain arbitrary command execution on WordPress servers by exploiting file upload validation bypass. Successful exploitation allows full server compromise via webshell deployment. High-value target due to 6 million+ installations. Exploitation requires published form with file upload field (common configuration). Patch available since August 19 (version 4.2.2).

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade Elementor Pro to version 4.2.2 or later on all WordPress installations
  • Inspect /wp-content/uploads/elementor/forms/ directory for any .php files; legitimate form uploads should not contain PHP files
  • Review web server access logs for POST requests to /wp-content/uploads/elementor/forms/*.php since August 19, 2026
  • Block known malicious IP addresses published by Wordfence in firewall rules
  • If compromise detected, perform full incident response including credential rotation, malware scan, and integrity verification of WordPress core and plugin files