Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical remote code execution flaw identified as CVE-2026-32475 affects versions of Elementor Pro prior to 4.2.2, allowing unauthenticated attackers to upload executable files to WordPress servers. The vulnerability arises from a mismatch between file validation and processing loops in the File Upload module, specifically when handling empty filename entries within multipart uploads.
Researchers at Patchstack disclosed that the exploit requires only a published Elementor form with a file upload field, enabling adversaries to place PHP payloads in public directories where they can be executed by the server. While no active exploitation has been observed yet, a proof-of-concept is available, urging administrators to immediately update to the fixed version and manually inspect their upload directories for malicious content.