Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Overview
Researchers have identified a serious vulnerability in the Elementor Pro plugin for WordPress, designated as CVE-2026-32475. This flaw, which has a CVSS score of 9.0, allows unauthenticated attackers to upload malicious PHP files and execute code on affected sites. The issue is found within the Forms module's file upload functionality, posing a significant risk to WordPress installations using this plugin. If exploited, this could lead to unauthorized access and control over websites, making it crucial for users and site administrators to address the issue promptly. As the vulnerability is particularly dangerous, it is essential for those using Elementor Pro to take immediate action to secure their sites.
Key Takeaways
- Affected Systems: Elementor Pro plugin for WordPress, specifically within the Forms module.
- Action Required: Users should update to the latest version of Elementor Pro as soon as a patch is available.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File
Impact
Elementor Pro plugin for WordPress, specifically within the Forms module.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should update to the latest version of Elementor Pro as soon as a patch is available. In the meantime, site administrators should consider disabling the Forms module or restricting file uploads to trusted file types until a fix is deployed.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical.