AUTO-UPDATED

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A critical vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, allows unauthenticated attackers to execute remote code by bypassing file upload restrictions on vulnerable websites.

Key Points

  • The flaw, rated 9.0 on the CVSS scale, affects all Elementor Pro versions up to and including 4.2.1.
  • Attackers can exploit the Forms module's File Upload field to upload malicious PHP scripts to public directories.
  • Security researcher Tin Pham discovered the vulnerability, which was subsequently patched in version 4.2.2 on August 19, 2026.
  • Exploitation requires only a published page containing an Elementor Form widget with a File Upload field.
  • WordPress also recently addressed a separate high-severity remote code execution vulnerability, CVE-2026-65640, in core versions up to 7.0.

Why it Matters

  • These vulnerabilities pose a significant risk to the vast ecosystem of WordPress sites that rely on common form-based interactions and media uploads. Failure to update plugins and core software leaves websites susceptible to full system compromise and integration into malicious botnet infrastructures.
Internet Published by info@thehackernews.com (The Hacker News)
Read original