Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-32475 in Elementor Pro lets an unauthenticated attacker bypass file-upload validation in the Forms module's File Upload field, write a PHP file into a public directory, and reach remote code execution on affected WordPress sites. The flaw affects plugin versions prior to and including 4.2.1 on sites that expose a published Elementor page with the vulnerable form field. Version 4.2.2 was released on 2026-08-19 to address the issue.
Timeline
-
20.08.2026 09:04 1 articles · 2h ago
Researcher reports CVE-2026-32475 to Elementor Pro
Initial DisclosureSecurity researcher Tin Pham, aka TF1T, reports the Elementor Pro Forms module file-upload flaw to Elementor Pro under the Patchstack Bug Bounty Program on July 16, 2026.
Show sources
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04
-
20.08.2026 09:04 1 articles · 2h ago
Elementor Pro 4.2.2 patches the file-upload RCE flaw
Mitigation Patch UpdateElementor releases version 4.2.2 on August 19, 2026 to address CVE-2026-32475 in the Elementor Pro Forms module File Upload field, closing the path that let an unauthenticated attacker bypass file-upload checks and write a PHP file into a public directory.
Show sources
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04
-
20.08.2026 09:04 2 articles · 2h ago
Patchstack details the Elementor Pro Forms File Upload bypass
Technical Analysis UpdateOn August 20, 2026, cybersecurity researchers disclose CVE-2026-32475 in the Elementor Pro WordPress plugin, explaining that the flaw in the Forms module's File Upload field lets an unauthenticated attacker skip the extension blocklist, write a PHP file to a public directory, and achieve remote code execution on affected sites running versions prior to and including 4.2.1.
Show sources
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — thehackernews.com — 20.08.2026 09:04