Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical flaw in Elementor Pro, tracked as CVE-2026-32475, can let attackers upload a malicious PHP file and achieve remote code execution on vulnerable WordPress servers. The issue affects Elementor Pro versions before 4.2.2 and only sites using a published Elementor Form with a File Upload field and the multiple file upload option enabled, with no active exploitation seen yet. #CVE-2026-32475 #ElementorPro #Patchstack #WordPress

Keypoints

  • CVE-2026-32475 affects Elementor Pro versions before 4.2.2.
  • The flaw is in the File Upload module and involves empty filename handling.
  • An attacker can bypass validation with a crafted multipart upload.
  • The payload can be moved into a public uploads directory and executed by PHP.
  • Administrators should update Elementor Pro and inspect the uploads directory for rogue files.

Read More: https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/