CVE-2026-32475
CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious… EPSS 2% (76th percentile).
Vulnerabilities & Exploits · Web App Attack
Patchstack says CVE-2026-32475 in Elementor Pro affects all versions through 4.2.1, and public technical details on day 13 show how a normal form upload can become unauthenticated code execution. The flaw sits in the Forms module's File Upload field, and the only precondition is a published page with that widget present.
The bug splits checking and handling into separate passes. By sending two file parts for the same field, an attacker can slip past the extension blocklist during validation and still have a PHP file written into a public uploads path under wp-content/uploads/elementor/forms, which turns the form into a webroot write primitive.
That leaves any WordPress site using Elementor Pro forms with upload fields carrying a site-wide compromise path until the vulnerable plugin version is out of service. The risk is conditional, not universal: sites without published upload forms do not have the same exposure, but where the widget exists the blast radius is the whole site, not just the submission feature.
7 sources · Aug 20
CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious… EPSS 2% (76th percentile).
BleepingComputer
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
originalThe Hacker News
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
originalSecurityWeek
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
originalPart of the PlainSec briefing for 2026-08-08
Every edition of this story: Elementor Pro Upload Check Opens PHP Write Path