Elementor Pro RCE Flaw CVE-2026-32475 Allows Unauthenticated File Upload Attacks
A critical unauthenticated remote code execution vulnerability, CVE-2026-32475, has been discovered in Elementor Pro, a widely used WordPress page-builder plugin. The flaw stems from a logic error in the file upload validation function, where a premature return statement skips extension and MIME-type checks for subsequent files in the same upload field, while a separate file-mover loop still processes and writes them. Any site hosting a published page with a non-required Elementor Form file upload field is exposed, requiring no authentication or nonce bypass since the form handler is accessible to unauthenticated users by design. The vulnerability was independently reported by Tin Pham via Patchstack on July 16 and by Austin Ginder via Wordfence's bug bounty program around July 24, with active exploitation observed in the wild during an attack peak between August 19 and 23. Site owners are urged to update immediately to Elementor Pro version 4.2.2 or later, and to add server-level rules blocking PHP execution under the forms upload directory as a defense-in-depth measure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in