Unrestricted File Upload Vulnerability in Elementor Pro by Elementor
CVE-2026-32475
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-32475?
CVE-2026-32475 is a critical vulnerability identified in the Elementor Pro plugin, which is used in conjunction with WordPress to facilitate the design and customization of websites. This vulnerability is categorized as an "Unrestricted File Upload Vulnerability," allowing attackers to upload files of malicious types without proper restrictions. The risk stems from the ability to exploit this flaw to execute arbitrary code on the server hosting the WordPress site. Such unauthorized access could lead to significant disruptions, including defacement of the website, unauthorized data access, or full server compromise. The affected versions include all releases from the inception of Elementor Pro up to version 4.2.1.
Potential impact of CVE-2026-32475
-
Remote Code Execution (RCE): Exploiting this vulnerability can allow attackers to execute arbitrary code on the server, leading to complete control over the website and its resources. This can result in data theft, website hijacking, or the installation of malware.
-
Data Breach and Exfiltration: Attackers can leverage the ability to upload malicious files to gain unauthorized access to sensitive data stored on the server. This could impact customer information, financial records, and other critical assets, leading to severe reputational and financial damage for organizations.
-
Web Defacement and Service Disruption: By gaining access through this vulnerability, malicious actors can alter the content displayed on the website or disrupt its functioning. This can lead to user mistrust and potential loss of business, particularly for e-commerce and service-oriented websites.
Affected Version(s)
Elementor Pro <= 4.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Hackers are exploiting a vulnerability (CVE-2026-32475) in the Elementor Pro plugin to hack WordPress sites.
2 weeks ago
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.
2 weeks ago
Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
2 weeks ago
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- π
Vulnerability started trending
- πΎ
Exploit known to exist
- π°
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved