A critical vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, allows unauthenticated attackers to execute remote code by bypassing file upload restrictions on vulnerable websites.
Key Points
- The flaw, rated 9.0 on the CVSS scale, affects all Elementor Pro versions up to and including 4.2.1.
- Attackers can exploit the Forms module's File Upload field to upload malicious PHP scripts to public directories.
- Security researcher Tin Pham discovered the vulnerability, which was subsequently patched in version 4.2.2 on August 19, 2026.
- Exploitation requires only a published page containing an Elementor Form widget with a File Upload field.
- WordPress also recently addressed a separate high-severity remote code execution vulnerability, CVE-2026-65640, in core versions up to 7.0.
Why it Matters
- These vulnerabilities pose a significant risk to the vast ecosystem of WordPress sites that rely on common form-based interactions and media uploads. Failure to update plugins and core software leaves websites susceptible to full system compromise and integration into malicious botnet infrastructures.