Critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News

Overview

Researchers have identified a serious vulnerability in the Elementor Pro plugin for WordPress, designated as CVE-2026-32475. This flaw, which has a CVSS score of 9.0, allows unauthenticated attackers to upload malicious PHP files and execute code on affected sites. The issue is found within the Forms module's file upload functionality, posing a significant risk to WordPress installations using this plugin. If exploited, this could lead to unauthorized access and control over websites, making it crucial for users and site administrators to address the issue promptly. As the vulnerability is particularly dangerous, it is essential for those using Elementor Pro to take immediate action to secure their sites.

Key Takeaways

  • Affected Systems: Elementor Pro plugin for WordPress, specifically within the Forms module.
  • Action Required: Users should update to the latest version of Elementor Pro as soon as a patch is available.
  • Timeline: Newly disclosed

Original Article Summary

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

Impact

Elementor Pro plugin for WordPress, specifically within the Forms module.

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should update to the latest version of Elementor Pro as soon as a patch is available. In the meantime, site administrators should consider disabling the Forms module or restricting file uploads to trusted file types until a fix is deployed.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

Managing the cyber risk of agentic AI

All Feed

The article discusses the importance of managing cyber risks associated with autonomous systems, particularly those powered by agentic AI. It emphasizes the need for safeguards, sandboxing, and active oversight to prevent unintended actions by these technologies. As AI systems become more autonomous, there's a growing concern about their potential to operate outside of intended parameters, which could lead to security vulnerabilities or harmful outcomes. By implementing these protective measures, organizations can harness the benefits of AI while minimizing risks to their operations and data security. This is increasingly relevant as more sectors integrate autonomous systems into their workflows.

Aug 20, 2026

New Manic Android malware can exfiltrate data through nearby devices

BleepingComputer

A new Android malware called Manic has emerged, targeting users across several European countries. This malware is particularly concerning because it can exfiltrate data not just through traditional means, but also by leveraging nearby infected devices. This makes it more difficult for users to detect and defend against. Researchers have identified the malware's ability to communicate with other compromised devices, potentially allowing attackers to gather sensitive information from a wider network of victims. This situation raises alarms about the security of Android devices and the need for users to be vigilant about app permissions and device security.

Aug 20, 2026

Police Are Hiding Their Use of Flock Surveillance Cameras

Schneier on Security

In Wapello County, Iowa, a policy regarding the use of Flock license plate reader cameras has come to light, revealing that police are instructed to keep their usage a secret from the public. The policy explicitly directs officers not to mention the Automated License Plate Recognition (ALPR) technology to individuals during stops or in their reports unless absolutely necessary. This raises concerns about transparency and accountability in law enforcement practices. The use of such surveillance tools without public awareness parallels past incidents involving IMSI-catchers, which were similarly concealed. The implications of this secrecy affect public trust and raise questions about the balance between security and individual rights.

Aug 20, 2026

Critical Zimbra RCE flaw now actively exploited in attacks

BleepingComputer

CERT Polska has alerted users that a serious vulnerability in Zimbra Collaboration Suite (ZCS) is currently being exploited by attackers. This flaw allows for remote code execution, which means that unauthorized individuals could potentially take control of affected systems. Organizations using ZCS should be particularly vigilant as this vulnerability poses a significant risk to their data and operations. Users are advised to check for updates and apply any available patches immediately to mitigate the risk. The situation is urgent as the exploitation of this vulnerability is already occurring in the wild, making timely action crucial for affected organizations.

Aug 20, 2026

Def Con Attendees Targeted by Persistent Phishing Campaign

Infosecurity Magazine

After attending the Def Con hacking conference, participants found themselves at the center of a sophisticated phishing campaign. Researchers from Huntress reported receiving targeted emails that attempted to deceive them into revealing sensitive information. These phishing attempts were not just random; they were persistent and tailored to exploit the knowledge and skills of conference attendees. This incident serves as a reminder of the ongoing risks faced by cybersecurity professionals, especially after major events where attackers may leverage the excitement and connections made during the conference. The implications are significant, as such attacks can lead to data breaches or identity theft if successful.

Aug 20, 2026

OpenAI previews privacy-focused system for detecting AI misuse

Help Net Security

OpenAI is introducing a new system called Private Safety Processing, aimed at enhancing privacy and security as AI technology continues to develop. This system is designed to detect patterns in user interactions while ensuring that OpenAI staff cannot access the actual content of those interactions. The initiative is in response to concerns from early customers about data protection and misuse of AI systems. OpenAI plans to roll out this system and release a technical white paper in September to provide further details. This move reflects a collaborative approach to addressing the challenges posed by advanced AI capabilities, emphasizing that no single company can tackle these risks alone.

Aug 20, 2026