started · updated
Elementor Pro vulnerability allows unauthenticated remote code execution
A critical security vulnerability, identified as CVE-2026-32475, has been discovered in the Elementor Pro WordPress plugin. The flaw affects versions up to and including 4.2.1 and allows unauthenticated attackers to perform remote code execution (RCE) on a target server.
The vulnerability resides in the plugin’s File Upload module within the Forms widget. It is caused by a discrepancy in how the plugin handles empty file entries during separate validation and processing loops. An attacker can bypass file extension restrictions by submitting a multipart upload containing an empty filename followed by a malicious PHP payload. This causes the validation routine to exit prematurely while the processing routine continues to save the malicious file into a public directory.
Security researchers note that exploitation is possible if a site has a published Elementor form with a File Upload field enabled. Elementor has released a patch in version 4.2.2 to address this issue. Administrators are urged to update their plugins immediately to mitigate the risk of complete site compromise.
Entities
Elementor · Elementor Pro · Forminator · Patchstack · Tin Pham · WordPress
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] The vulnerability requires a published Elementor form containing a File Upload field to be exploitable. cybernoz.com · www.blogspan.net · cybersecuritynews.com
- [● 4 SOURCES] Exploitation of the flaw allows unauthenticated attackers to upload malicious PHP files and achieve remote code execution. cybernoz.com · www.it-boltwise.de · www.blogspan.net · cybersecuritynews.com
- [● 4 SOURCES] The critical vulnerability in Elementor Pro is tracked as CVE-2026-32475. cybernoz.com · www.it-boltwise.de · www.blogspan.net · cybersecuritynews.com
- [● 4 SOURCES] The vulnerability is resolved in Elementor Pro version 4.2.2. cybernoz.com · www.it-boltwise.de · www.blogspan.net · cybersecuritynews.com
- [○ 1 SOURCE] The Elementor Pro vulnerability stems from inconsistent handling of empty file entries between validation and processing loops. cybernoz.com
- [● 3 SOURCES] Elementor Pro versions up to and including 4.2.1 are affected by the vulnerability. cybernoz.com · www.blogspan.net · cybersecuritynews.com