CVE-2026-32475
CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious… EPSS 2% (76th percentile).
Vulnerabilities · 39 days ago
Patchstack says CVE-2026-32475 in Elementor Pro affects all versions through 4.2.1, and public technical details on day 13 show how a normal form upload can become unauthenticated code execution. The flaw sits in the Forms module's File Upload field, and the only precondition is a published page with that widget present.
The bug splits checking and handling into separate passes. By sending two file parts for the same field, an attacker can slip past the extension blocklist during validation and still have a PHP file written into a public uploads path under wp-content/uploads/elementor/forms, which turns the form into a webroot write primitive.
That leaves any WordPress site using Elementor Pro forms with upload fields carrying a site-wide compromise path until the vulnerable plugin version is out of service. The risk is conditional, not universal: sites without published upload forms do not have the same exposure, but where the widget exists the blast radius is the whole site, not just the submission feature.
CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious… EPSS 2% (76th percentile).
7 sources covering this story
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
Sanata vulnerabilità in WordPress
Sanata una vulnerabilità con gravità “alta” in WordPress.
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
Subida de archivos sin restricciones en WordPress
WordPress ha publicado 1 vulnerabilidad de severidad alta que, en caso de ser explotada, podría permit
WordPress Plugins Compromised Without a Single File Change
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
Vulnerability in Magnolia CMS software
Stored Cross-Site Scripting vulnerability (CVE-2026-18478) has been found in Magnolia CMS software.
WordPress: PoC pubblico per lo sfruttamento della CVE-2026-64638
Disponibile un Proof of Concept (PoC) per la vulnerabilità identificata dalla CVE-2026-64638, già sanata dal vendor, che interessa il noto CMS WordPress.
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
Part of the PlainSec briefing for 2026-08-08