← Back to blog

Critical Elementor Pro Flaw Exposes Sites to Remote Code Execution

A severe vulnerability in Elementor Pro allows unauthenticated attackers to upload malicious PHP files. WordPress sites using the plugin should update immediately.

TL;DR

  • CVE-2026-32475 is a critical file upload flaw in Elementor Pro with a CVSS score of 9.0
  • Unauthenticated attackers can exploit it to execute arbitrary PHP code on affected sites
  • The vulnerability resides in the Forms module's file handling functionality
  • Sites using Elementor Pro should apply updates as soon as possible
  • No authentication required makes this vulnerability particularly dangerous

Website owners and developers relying on Elementor Pro for WordPress site building face a serious security threat. A newly disclosed vulnerability could allow attackers to execute arbitrary code without needing login credentials.

The flaw affects the popular page builder's Forms module, specifically its handling of file uploads. With a severity rating of 9.0 out of 10.0, CVE-2026-32475 represents a significant risk to thousands of websites still running unpatched versions.

Vulnerability Details

  • CVE-2026-32475 is classified as an unrestricted file upload vulnerability
  • It affects Elementor Pro's Forms module where file validation is insufficient
  • Attackers can upload PHP files without proper authentication
  • Successful exploitation leads to remote code execution capabilities
  • CVSS score of 9.0 indicates critical severity level

Impact and Mitigation

  • All WordPress sites using Elementor Pro are potentially vulnerable
  • No user authentication required for exploitation makes it especially dangerous
  • Immediate patching is recommended for all affected installations
  • Site administrators should verify their Elementor Pro version is updated
  • Consider monitoring server logs for suspicious file uploads as temporary measure

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.