CVE-2026-32475

Published Aug 19, 2026

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32475 is an "Unrestricted Upload of File with Dangerous Type" vulnerability found in Elementor Pro versions up to 4.2.1. This flaw allows an unauthenticated attacker to upload malicious files, typically PHP files, through the Forms module's File Upload field. The vulnerability arises because the file validation and processing routines within the plugin handle empty file entries differently, enabling an attacker to bypass security checks. By exploiting this discrepancy, an attacker can upload an unchecked file, which can then be executed on the server. This can lead to remote code execution and potential compromise of the affected WordPress site. The issue has been addressed in Elementor Pro version 4.2.2.

Description
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
Source
audit@patchstack.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-434

Social media

Hype score
Not currently trending
  1. CVE-2026-14894 | CVE-2026-32475 unauthenticated arbitrary file upload PoC: https://t.co/TGnfo6yA5N #CyberSecurity #InfoSec #0day #CVE #EthicalHacking #ExploitDev #WordPress

    @Nxploited

    21 Sept 2026

    147 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Good morning. Elementor Pro CVE-2026-32475 isn't theoretical anymore Wordfence alone has blocked 200,000 exploitation attempts since the Aug 19 patch If you're running Elementor Pro, update AND check uploads/elementor/forms/ for PHP files that shouldn't be there. Happy Monday.

    @iamjustape

    7 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-32475 Elementor Pro 취약점 — 인증 없이 PHP 파일 업로드·사이트 장악 위험과 대응 https://t.co/xajnyBNFX9

    @J_zjaan7946

    7 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Elementor Pro CVE-2026-32475 on aktiivisessa hyväksikäytössä WordPress-sivustoilla https://t.co/xAGefuoW8A https://t.co/eaCAKM7YLk

    @n1xupartanen

    6 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Hackers are exploiting a vulnerability (CVE-2026-32475) in the Elementor Pro plugin to hack WordPress sites. https://t.co/Y59Yyl1jDU https://t.co/2c1ZMprMbP

    @StetsonCG

    6 Sept 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Elementor Pro WordPress plugin critical vuln (CVE-2026-32475, CVSS 9.8) exploited for arbitrary file uploads & site hacks. #CyberAttack #WordPress #Vulnerability

    @chris_uk2026

    6 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 【報道:WordPressサイトが狙われる】 ・Elementor Proに重大な脆弱性 ・フォームのファイル検証に不具合 ・CVE-2026-32475、CVSS 9.8 報道によると、更新判断を急ぐ局面です。 #脆弱性管理 https://t.co/ViQsQbWHPN

    @eng_digest_jp

    6 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Popular Elementor Pro #WordPress Plugin Vulnerability Exploited to Hack Sites (CVE-2026-32475) - https://t.co/G8IGlFDBzo

    @SecurityWeek

    5 Sept 2026

    2759 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  9. CVE-2026-32475 (CVSS 9.0) in Elementor Pro lets unauthenticated attackers bypass file extension checks and drop executable PHP files into wp-content/uploads/elementor/forms/. Over 190,000 exploitation attempts were blocked August 19-23. #DFIR_Radar https://t.co/iXzO8VqwMs

    @DFIR_Radar

    5 Sept 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Over 440,000 attacks blocked targeting Super Forms and Elementor Pro flaws (CVE-2026-14894, CVE-2026-32475) allowing unauthenticated RCE on WordPress. Update now. #WordPress #CyberSecurity #RCE https://t.co/kJSdBxTByD

    @CyberWorldOps

    5 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔴 CVE-2026-32475 — Elementor Pro under mass attack Wordfence has blocked 190,000+ exploitation attempts targeting this critical WordPress flaw. Attackers can abuse vulnerable forms to upload https://t.co/3WFFNJcAmk #CVE #CVE202632475 #Elementor #WordPress #RCE #CyberSecur

    @stem__shop

    5 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2026-14894 and CVE-2026-32475 attracted over 440,000 blocked exploit attempts. Wordfence logged more than 250,000 requests against the Super Forms flaw and 190,000 against Elementor Pro. CVE-2026-14894 in Super Forms before 6.3.314 accepts an unauthenticated POST to

    @SecureChap

    4 Sept 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 WordPress'te 440 Bin+ İstismar Girişimi Super Forms ve Elementor Pro açıkları aktif olarak sömürülüyor. Saldırganlar PHP webshell yükleyerek sitelerde uzaktan kod çalıştırabiliyor. CVE-2026-14894 (9.8) ve CVE-2026-32475 (9.0+) için güncelleme kritik. #Wor

    @KubbeSiber

    4 Sept 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 440,000+ exploit attempts. Two WordPress plugins. Full RCE. Attackers are actively targeting: 🔴 Super Forms — CVE-2026-14894 (9.8) 🔴 Elementor Pro — CVE-2026-32475 (9.0/9.8) The flaws allow unauthenticated attackers to upload malicious PHP files and execute code

    @thecybersecguru

    4 Sept 2026

    133 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Massive wave of exploit attempts against WordPress plugins: Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) are under fire. Over 440,000 attacks blocked, with unauthenticated PHP upload flaws allowing remote code execution. Patch sites now and audit your uploads &

    @dailytechonx

    4 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. الثغرتين CVE-2026-14894 ، CVE-2026-32475 على #WordPress site https://t.co/1v1LUczhg8 https://t.co/pFL1Rzk9nb

    @_MahaKSA

    4 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Elementor Pro sotto attacco: CVE-2026-32475 sfruttata oltre 190.000 volte Vulnerabilità, Wordpress https://t.co/xvLfhSCGzq https://t.co/R6sMJ52Wrx

    @matricedigitale

    4 Sept 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🔍Nightmare Eclipse、CrowdStrike Falconの特権昇格ゼロデイPoCをリリース 🚨Elementor Proの重大な脆弱性、WordPressサイトの乗っ取り目的で悪用される:CVE-2026-32475 〜サイバーアラート9月4日〜 https://t.co/QRjDw39Wp3

    @MachinaRecord

    4 Sept 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. TRC analysis shows attackers exploiting CVE-2026-32475 in Elementor Pro to deploy PHP webshells on WordPress sites. Nearly 200,000 exploitation attempts recorded within days, with successful server compromise enabling lateral movement across hosting environments. #Vulnerability

    @aviatrixtrc

    4 Sept 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2026-32475: Elementor Pro RCE Exploited in the Wild - https://t.co/aYIIOAWY2q

    @moton

    3 Sept 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Elementor Pro CVE-2026-32475 affects every version ever shipped up to 4.2.1. The part nobody mentions: it's a licensed plugin. Lapsed licence means the update button doesn't work, and no host can push it for you. https://t.co/kJM6cO68y4

    @CodyConsultant

    2 Sept 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Elementor Pro's changelog barely mentioned CVE-2026-32475 (unauth upload to RCE), and its exposure claim to customers was narrower than what Patchstack and Wordfence found. It also doesn't auto-update from WordPress. https://t.co/4VySlRq8wm #WordPressSecurity #CVE

    @magicwp_io

    25 Aug 2026

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Elementor Pro CVE-2026-32475──未認証でPHP実行(RCE)、確認と4.2.2更新手順 https://t.co/HZtX4o8nEw #Qiita @sitedock_jpより

    @yousukezan

    23 Aug 2026

    1513 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Elementor Pro has critical unauthenticated file upload flaw CVE-2026-32475 CVSS 9.0, allowing PHP uploads via Forms and code execution. Update now, audit upload forms. For businesses, security hygiene, patching speed, upload endpoint audits core skills.

    @webforall_

    22 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 Critical #ElementorPro vulnerability CVE-2026-32475 could let attackers upload malicious PHP files and achieve remote code execution on vulnerable #WordPress sites. Read here: https://t.co/6lfWrKQJxh #CyberSecurity #RCE #CVE #WordPressSecurity

    @ClearPhish

    21 Aug 2026

    115 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  26. Poc CVE-2026-32475 Elementor Pro Unauthenticated File Upload to RCE #wordpress #rec #elementor https://t.co/3bEXjrhtO5

    @absholi7ly

    20 Aug 2026

    3288 Impressions

    9 Retweets

    50 Likes

    27 Bookmarks

    1 Reply

    1 Quote

  27. 🚨 Vulnerabilidad crítica en Elementor Pro. CVE-2026-32475 puede permitir a atacantes no autenticados subir PHP y alcanzar ejecución remota de código en servidores WordPress vulnerables. Más información: https://t.co/zmKUpGAkPG #CyberSecurity #WordPress #CVE #Hacking

    @Bussio28Team

    20 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes