A critical flaw in Elementor Pro, tracked as CVE-2026-32475, can let attackers upload a malicious PHP file and achieve remote code execution on vulnerable WordPress servers. The issue affects Elementor Pro versions before 4.2.2 and only sites using a published Elementor Form with a File Upload field and the multiple file upload option enabled, with no active exploitation seen yet. #CVE-2026-32475 #ElementorPro #Patchstack #WordPress
Keypoints
- CVE-2026-32475 affects Elementor Pro versions before 4.2.2.
- The flaw is in the File Upload module and involves empty filename handling.
- An attacker can bypass validation with a crafted multipart upload.
- The payload can be moved into a public uploads directory and executed by PHP.
- Administrators should update Elementor Pro and inspect the uploads directory for rogue files.