CVE Tools
Back to feed
Patch released Elementor Pro rce WordPress Elementor web-app

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Researchers have identified a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to achieve remote code execution through file upload manipulation. Tracked as CVE-2026-32475 with a CVSS score of 9.0, the flaw exists in the Forms module's File Upload field, where discrepancies in extension checking and file handling permit the bypass of security restrictions. This issue affects all versions of Elementor Pro up to 4.2.1, but has been resolved in the recently released version 4.2.2.