TTO-2026-0903-003 · September 3, 2026 Active ExploitationCritical

Elementor Pro CVE-2026-71460 CVSS 9.8 Actively Exploited — Unauthenticated Attackers Taking Over WordPress Sites at Scale

elementor.comCVE-2026-71460 CVSS 9.8Unauthenticated privilege escalation12 million active installsBroken access controladmin_ajax.phpPatched in 3.28.4Mass scanning observedWordfence 700 attack blocks in 24 hours

Summary

Wordfence confirmed on September 2, 2026 that CVE-2026-71460, a critical broken access control vulnerability in Elementor Pro, the premium WordPress page builder plugin with more than 12 million active installations, is being actively exploited at scale. The vulnerability allows unauthenticated attackers to modify WordPress site options by abusing an improperly secured admin_ajax.php action registered by Elementor Pro's WooCommerce module. The vulnerable action is available to unauthenticated users, and it permits modification of arbitrary WordPress site options including the default user role — which an attacker can set to Administrator — and the user registration toggle — which can be enabled to allow self-registration. Once these options are manipulated, the attacker registers a new account that automatically receives administrator privileges, achieving full site takeover without exploiting any additional vulnerability. Wordfence reported blocking more than 700 attacks against its users within a 24-hour window following its September 2 disclosure. The vulnerability was patched in Elementor Pro version 3.28.4. Sites running any prior version with the WooCommerce integration active remain vulnerable. Elementor Pro's free counterpart, the Elementor plugin, is not affected.

Timeline

DateEvent
Aug 2026CVE-2026-71460 discovered and reported to Elementor
Aug 2026Elementor Pro releases version 3.28.4 — patches CVE-2026-71460
Sep 2, 2026Wordfence publishes disclosure — confirms active exploitation — blocks 700+ attacks in 24 hours
Sep 3, 2026Mass scanning ongoing — 12 million installs — sites with WooCommerce integration on unpatched versions at immediate risk

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
elementor.com62.28✓✓✓Live
WarmBadge Intelligence Snapshot · Captured: September 3, 2026 UTC

Context

elementor.com scores 62.28 — a low-trust range score for a WordPress ecosystem company whose premium plugin is deployed on 12 million sites. The exploitation chain for CVE-2026-71460 requires no authentication and no technical sophistication: enable registration, set default role to Administrator, register an account. That is a three-step site takeover accessible to any attacker who can send an HTTP request. The 700-attack-in-24-hours figure from Wordfence represents only the subset of attacks intercepted by Wordfence-protected sites. The actual scanning and exploitation volume across all 12 million Elementor Pro installations is substantially larger. Any WordPress site running Elementor Pro with WooCommerce integration on a version below 3.28.4 should treat that as an active incident rather than a pending patch item.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 3, 2026