Critical Elementor Pro Flaw Exposes Sites to Remote Code Execution
A severe vulnerability in Elementor Pro allows unauthenticated attackers to upload malicious PHP files. WordPress sites using the plugin should update immediately.
TL;DR
- CVE-2026-32475 is a critical file upload flaw in Elementor Pro with a CVSS score of 9.0
- Unauthenticated attackers can exploit it to execute arbitrary PHP code on affected sites
- The vulnerability resides in the Forms module's file handling functionality
- Sites using Elementor Pro should apply updates as soon as possible
- No authentication required makes this vulnerability particularly dangerous
Website owners and developers relying on Elementor Pro for WordPress site building face a serious security threat. A newly disclosed vulnerability could allow attackers to execute arbitrary code without needing login credentials.
The flaw affects the popular page builder's Forms module, specifically its handling of file uploads. With a severity rating of 9.0 out of 10.0, CVE-2026-32475 represents a significant risk to thousands of websites still running unpatched versions.
Vulnerability Details
- CVE-2026-32475 is classified as an unrestricted file upload vulnerability
- It affects Elementor Pro's Forms module where file validation is insufficient
- Attackers can upload PHP files without proper authentication
- Successful exploitation leads to remote code execution capabilities
- CVSS score of 9.0 indicates critical severity level
Impact and Mitigation
- All WordPress sites using Elementor Pro are potentially vulnerable
- No user authentication required for exploitation makes it especially dangerous
- Immediate patching is recommended for all affected installations
- Site administrators should verify their Elementor Pro version is updated
- Consider monitoring server logs for suspicious file uploads as temporary measure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.