< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Elementor Pro vulnerability allows unauthenticated remote code execution

A critical security vulnerability, identified as CVE-2026-32475, has been discovered in the Elementor Pro WordPress plugin. The flaw affects versions up to and including 4.2.1 and allows unauthenticated attackers to perform remote code execution (RCE) on a target server.

The vulnerability resides in the plugin’s File Upload module within the Forms widget. It is caused by a discrepancy in how the plugin handles empty file entries during separate validation and processing loops. An attacker can bypass file extension restrictions by submitting a multipart upload containing an empty filename followed by a malicious PHP payload. This causes the validation routine to exit prematurely while the processing routine continues to save the malicious file into a public directory.

Security researchers note that exploitation is possible if a site has a published Elementor form with a File Upload field enabled. Elementor has released a patch in version 4.2.2 to address this issue. Administrators are urged to update their plugins immediately to mitigate the risk of complete site compromise.

Entities

Elementor · Elementor Pro · Forminator · Patchstack · Tin Pham · WordPress

Claims

What the coverage asserts, and how many sources carry each claim.