Find notable cyber news and cases, enriched with sources, timelines, and signals.

Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-32475 in Elementor Pro lets an unauthenticated attacker bypass file-upload validation in the Forms module's File Upload field, write a PHP file into a public directory, and reach remote code execution on affected WordPress sites. The flaw affects plugin versions prior to and including 4.2.1 on sites that expose a published Elementor page with the vulnerable form field. Version 4.2.2 was released on 2026-08-19 to address the issue.

Timeline

  1. 20.08.2026 09:04 1 articles · 2h ago

    Elementor Pro 4.2.2 patches the file-upload RCE flaw

    Mitigation Patch Update

    Elementor releases version 4.2.2 on August 19, 2026 to address CVE-2026-32475 in the Elementor Pro Forms module File Upload field, closing the path that let an unauthenticated attacker bypass file-upload checks and write a PHP file into a public directory.

    Show sources
  2. 20.08.2026 09:04 2 articles · 2h ago

    Patchstack details the Elementor Pro Forms File Upload bypass

    Technical Analysis Update

    On August 20, 2026, cybersecurity researchers disclose CVE-2026-32475 in the Elementor Pro WordPress plugin, explaining that the flaw in the Forms module's File Upload field lets an unauthenticated attacker skip the extension blocklist, write a PHP file to a public directory, and achieve remote code execution on affected sites running versions prior to and including 4.2.1.

    Show sources