THREAT OPS › Threat News › Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
<p>On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://elementor.com/pro/" rel="noopener" target="_blank">Elementor Pro</a>, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulne
MITRE ATT&CK techniques
Indicators of compromise
- 8ec93bb7e5ec96ab4636699e413382c9md5
- 4ecc8b71d0984f421844d12e862a7638md5
- b6761add721875da77ab27c1c43430bamd5
- CVE-2026-32475cve
- https://elementor.com/pro/url
- https://www.cve.org/CVERecord?id=CVE-2026-32475url
- 185.196.220.85ipv4
- 103.84.230.85ipv4
- 103.90.148.202ipv4
- 216.126.225.208ipv4
- 167.254.240.75ipv4
- 167.254.241.119ipv4
- 114.10.17.253ipv4
- 114.10.45.151ipv4
- www.gravatar.comdomain