Patch released Elementor Pro rce WordPress Elementor web-app
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
CVE Tools coverage
Researchers have identified a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to achieve remote code execution through file upload manipulation. Tracked as CVE-2026-32475 with a CVSS score of 9.0, the flaw exists in the Forms module's File Upload field, where discrepancies in extension checking and file handling permit the bypass of security restrictions. This issue affects all versions of Elementor Pro up to 4.2.1, but has been resolved in the recently released version 4.2.2.