Act
active
Critical Elementor Pro flaw exploited to drop webshells on WordPress
- Engineer — Act: Active exploitation delivering server-side webshells means any WordPress instance running Elementor Pro is at immediate risk; patch to the latest Elementor Pro release now and audit wp-content directories for unexpected PHP files or recently modified files indicative of webshell drops.
- SOC/IR — Act: Exploitation is confirmed in the wild with webshell payloads executing arbitrary commands; hunt for anomalous file-creation events under wp-content on WordPress servers and flag outbound connections or command execution originating from web server processes since the start of active campaign reports.
- Leader — Skip
- Signals: CVE-2026-32475 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.