CuraSec

Act active

Critical Elementor Pro flaw exploited to drop webshells on WordPress

2026-09-03 14:58 UTC · BleepingComputer · read the source ↗ #wordpress#webshell#exploitation
  • Engineer — Act: Active exploitation delivering server-side webshells means any WordPress instance running Elementor Pro is at immediate risk; patch to the latest Elementor Pro release now and audit wp-content directories for unexpected PHP files or recently modified files indicative of webshell drops.
  • SOC/IR — Act: Exploitation is confirmed in the wild with webshell payloads executing arbitrary commands; hunt for anomalous file-creation events under wp-content on WordPress servers and flag outbound connections or command execution originating from web server processes since the start of active campaign reports.
  • Leader — Skip
  • Signals: CVE-2026-32475 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.