Elementor Pro bug CVE-2026-32475 can let attackers run code on vulnerable WordPress sites

A critical flaw in the paid Elementor Pro plugin for WordPress can let attackers upload a malicious file and take over vulnerable websites. The bug, CVE-2026-32475, affects Elementor Pro before 4.2.2 and abuses the Form widget’s File Upload field when multiple file upload is enabled, using mismatched validation and processing of empty filenames to place attacker-controlled PHP files in a public uploads directory for remote code execution.
Why it matters: Sites using Elementor Pro forms with file uploads could be taken over remotely, so administrators should update to 4.2.2 immediately and inspect wp-content/uploads/elementor/forms/ for rogue PHP or other unexpected files. Even if no in-the-wild exploitation is confirmed yet, the attack path is clear and the plugin is widely deployed.

Sources

Critical Elementor Pro bug exposes WordPress sites to RCE attacks
Bill Toulas 2026.08.20 100% relevant
This article establishes a distinct new vulnerability story centered on CVE-2026-32475 in Elementor Pro, with affected versions, exploit conditions, patch availability, and mitigation guidance.
← Back to all stories