Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
Summary
Hide ▲
Show ▼
Elementor Pro released version 4.2.2 to fix CVE-2026-32475, closing an unauthenticated file-upload RCE path in the WordPress plugin. The update targets the Forms module's File Upload field and removes a flaw that could let an attacker write a PHP file into a public directory. Sites still running 4.2.1 or earlier need the patch to eliminate the exposed code-execution path.
Related Happenings
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48395
Security Patch Release
H score39
First: 01.08.2026 10:12
Last: 01.08.2026 10:12
Sources 1
About this happening:
Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Adobe security patch release for CVE-2026-48395
Security Patch ReleaseAbout this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Avada Builder 3.15.3 patch release (CVE-2026-4782, CVE-2026-4798)
Security Patch Release
H score21
First: 15.05.2026 18:56
Last: 15.05.2026 18:56
Sources 1
About this happening:
Avada Builder shipped version 3.15.3 as the full fix for CVE-2026-4782 and CVE-2026-4798, closing the plugin flaws that could expose files and database data. A pri...
Avada Builder 3.15.3 patch release (CVE-2026-4782, CVE-2026-4798)
Security Patch ReleaseAbout this happening: Avada Builder shipped version 3.15.3 as the full fix for CVE-2026-4782 and CVE-2026-4798, closing the plugin flaws that could expose files and database data. A pri...
Timeline
-
20.08.2026 09:04 2 articles · 2h ago
Elementor Pro releases 4.2.2 to fix CVE-2026-32475
Mitigation Patch UpdateElementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475. The patch closes the unauthenticated file-upload path in the Forms module's File Upload field that could let an attacker write a PHP file into wp-content/uploads/elementor/forms/<uniqid>.php and achieve remote code execution.
Show sources
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04
-
16.07.2026 03:00 1 articles · 1mo ago
Elementor Pro receives report of an unauthenticated file-upload RCE flaw
Initial DisclosurePatchstack says Tin Pham (aka TF1T) reported CVE-2026-32475 to Elementor Pro on July 16, 2026. The flaw is in the Forms module's File Upload field, where an unauthenticated attacker can bypass file-upload checks, write a PHP file into a public directory, and reach remote code execution on sites running Elementor Pro versions prior to and including 4.2.1.
Show sources
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04