A critical flaw in the paid Elementor Pro plugin for WordPress can let attackers upload a malicious file and take over vulnerable websites. The bug, CVE-2026-32475, affects Elementor Pro before 4.2.2 and abuses the Form widget’s File Upload field when multiple file upload is enabled, using mismatched validation and processing of empty filenames to place attacker-controlled PHP files in a public uploads directory for remote code execution.
Why it matters: Sites using Elementor Pro forms with file uploads could be taken over remotely, so administrators should update to 4.2.2 immediately and inspect wp-content/uploads/elementor/forms/ for rogue PHP or other unexpected files. Even if no in-the-wild exploitation is confirmed yet, the attack path is clear and the plugin is widely deployed.
Bill Toulas
2026.08.20
100% relevant
This article establishes a distinct new vulnerability story centered on CVE-2026-32475 in Elementor Pro, with affected versions, exploit conditions, patch availability, and mitigation guidance.
← Back to all stories