AI description
CVE-2026-32475 is an "Unrestricted Upload of File with Dangerous Type" vulnerability found in Elementor Pro versions up to 4.2.1. This flaw allows an unauthenticated attacker to upload malicious files, typically PHP files, through the Forms module's File Upload field. The vulnerability arises because the file validation and processing routines within the plugin handle empty file entries differently, enabling an attacker to bypass security checks. By exploiting this discrepancy, an attacker can upload an unchecked file, which can then be executed on the server. This can lead to remote code execution and potential compromise of the affected WordPress site. The issue has been addressed in Elementor Pro version 4.2.2.
- Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
- Source
- audit@patchstack.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- audit@patchstack.com
- CWE-434
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
Elementor Pro has critical unauthenticated file upload flaw CVE-2026-32475 CVSS 9.0, allowing PHP uploads via Forms and code execution. Update now, audit upload forms. For businesses, security hygiene, patching speed, upload endpoint audits core skills.
@webforall_
22 Aug 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical #ElementorPro vulnerability CVE-2026-32475 could let attackers upload malicious PHP files and achieve remote code execution on vulnerable #WordPress sites. Read here: https://t.co/6lfWrKQJxh #CyberSecurity #RCE #CVE #WordPressSecurity
@ClearPhish
21 Aug 2026
115 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
Poc CVE-2026-32475 Elementor Pro Unauthenticated File Upload to RCE #wordpress #rec #elementor https://t.co/3bEXjrhtO5
@absholi7ly
20 Aug 2026
3288 Impressions
9 Retweets
50 Likes
27 Bookmarks
1 Reply
1 Quote
🚨 Vulnerabilidad crítica en Elementor Pro. CVE-2026-32475 puede permitir a atacantes no autenticados subir PHP y alcanzar ejecución remota de código en servidores WordPress vulnerables. Más información: https://t.co/zmKUpGAkPG #CyberSecurity #WordPress #CVE #Hacking
@Bussio28Team
20 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes