Vulnerabilities · 39 days ago

Elementor Pro Upload Check Opens PHP Write Path

Patchstack says CVE-2026-32475 in Elementor Pro affects all versions through 4.2.1, and public technical details on day 13 show how a normal form upload can become unauthenticated code execution. The flaw sits in the Forms module's File Upload field, and the only precondition is a published page with that widget present.

The bug splits checking and handling into separate passes. By sending two file parts for the same field, an attacker can slip past the extension blocklist during validation and still have a PHP file written into a public uploads path under wp-content/uploads/elementor/forms, which turns the form into a webroot write primitive.

That leaves any WordPress site using Elementor Pro forms with upload fields carrying a site-wide compromise path until the vulnerable plugin version is out of service. The risk is conditional, not universal: sites without published upload forms do not have the same exposure, but where the widget exists the blast radius is the whole site, not just the submission feature.

CVE-2026-32475

NVD KEV

CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious… EPSS 2% (76th percentile).

Timeline

Sources

7 sources covering this story

Entities

Part of the PlainSec briefing for 2026-08-08

Editions

Related stories