Search
Find merged stories by title or summary.
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4. 2. 1 and is fixed in version 4. 2. 2. Elementor Pro is a premium extension for the Elementor page builder. Its Forms widget lets website owners create contact, job application, support, and document-submission forms. The vulnerable feature is the File Upload field that allows visitors to attach files. The flaw exists because the plugin handles file validation and file storage in separate loops. Under normal conditions, Elementor Pro checks uploaded file extensions against an allowlist and a blocklist. Dangerous extensions such as . php, . phtml, . asp, and . exe should be rejected.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9. 0 out of 10. 0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File
CVE-2026-32475 - National Institute of Standards and Technology (.gov)
CVE-2026-32475 National Institute of Standards and Technology (.gov)
You've reached the end of current stories for this search.
