Unrestricted File Upload Vulnerability in Elementor Pro by Elementor
CVE-2026-32475

9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2026

What is CVE-2026-32475?

Elementor Pro has a vulnerability that allows attackers to upload files of dangerous types without restriction. This can lead to potential exploits where malicious files are executed on the server. It is essential for users of Elementor Pro, particularly versions from n/a to 4.2.1, to patch this vulnerability promptly to protect their websites from unauthorized access and data breaches.

Affected Version(s)

Elementor Pro <= 4.2.1

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tin Pham aka TF1T | Patchstack Bug Bounty Program
.