CVE-2026-32475

Published Aug 19, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32475 is an "Unrestricted Upload of File with Dangerous Type" vulnerability found in Elementor Pro versions up to 4.2.1. This flaw allows an unauthenticated attacker to upload malicious files, typically PHP files, through the Forms module's File Upload field. The vulnerability arises because the file validation and processing routines within the plugin handle empty file entries differently, enabling an attacker to bypass security checks. By exploiting this discrepancy, an attacker can upload an unchecked file, which can then be executed on the server. This can lead to remote code execution and potential compromise of the affected WordPress site. The issue has been addressed in Elementor Pro version 4.2.2.

Description
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
Source
audit@patchstack.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-434

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1