Summary
Wordfence confirmed on September 2, 2026 that CVE-2026-71460, a critical broken access control vulnerability in Elementor Pro, the premium WordPress page builder plugin with more than 12 million active installations, is being actively exploited at scale. The vulnerability allows unauthenticated attackers to modify WordPress site options by abusing an improperly secured admin_ajax.php action registered by Elementor Pro's WooCommerce module. The vulnerable action is available to unauthenticated users, and it permits modification of arbitrary WordPress site options including the default user role — which an attacker can set to Administrator — and the user registration toggle — which can be enabled to allow self-registration. Once these options are manipulated, the attacker registers a new account that automatically receives administrator privileges, achieving full site takeover without exploiting any additional vulnerability. Wordfence reported blocking more than 700 attacks against its users within a 24-hour window following its September 2 disclosure. The vulnerability was patched in Elementor Pro version 3.28.4. Sites running any prior version with the WooCommerce integration active remain vulnerable. Elementor Pro's free counterpart, the Elementor plugin, is not affected.
Timeline
| Date | Event |
|---|---|
| Aug 2026 | CVE-2026-71460 discovered and reported to Elementor |
| Aug 2026 | Elementor Pro releases version 3.28.4 — patches CVE-2026-71460 |
| Sep 2, 2026 | Wordfence publishes disclosure — confirms active exploitation — blocks 700+ attacks in 24 hours |
| Sep 3, 2026 | Mass scanning ongoing — 12 million installs — sites with WooCommerce integration on unpatched versions at immediate risk |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| elementor.com | 62.28 | ✓ | ✓ | ✓ | Live |
Context
elementor.com scores 62.28 — a low-trust range score for a WordPress ecosystem company whose premium plugin is deployed on 12 million sites. The exploitation chain for CVE-2026-71460 requires no authentication and no technical sophistication: enable registration, set default role to Administrator, register an account. That is a three-step site takeover accessible to any attacker who can send an HTTP request. The 700-attack-in-24-hours figure from Wordfence represents only the subset of attacks intercepted by Wordfence-protected sites. The actual scanning and exploitation volume across all 12 million Elementor Pro installations is substantially larger. Any WordPress site running Elementor Pro with WooCommerce integration on a version below 3.28.4 should treat that as an active incident rather than a pending patch item.
The Trust Observatory · thetrustobservatory.com · September 3, 2026