CVE Tools

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

BleepingComputerBy Bill Toulas

PoC publicElementor Pro

Our summary

A critical remote code execution flaw identified as CVE-2026-32475 affects versions of Elementor Pro prior to 4.2.2, allowing unauthenticated attackers to upload executable files to WordPress servers. The vulnerability arises from a mismatch between file validation and processing loops in the File Upload module, specifically when handling empty filename entries within multipart uploads.

Researchers at Patchstack disclosed that the exploit requires only a published Elementor form with a file upload field, enabling adversaries to place PHP payloads in public directories where they can be executed by the server. While no active exploitation has been observed yet, a proof-of-concept is available, urging administrators to immediately update to the fixed version and manually inspect their upload directories for malicious content.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store