Elementor Pro, one of the most popular WordPress, is vulnerable to a critical vulnerability that could allow unauthorized attackers to upload PHP files and execute code remotely. The vulnerability, tracked as CVE-2026-32475, is rated CVSS 9.0 out of 10.The discovery comes at a time when the WordPress ecosystem is facing increased attacks through vulnerabilities in plugins and themes.

The vulnerability was found in the Forms module of Elementor Pro, specifically in the File Upload. The problem lies in a mismatch between two different processing loops: checking the file extension and moving the file to its final destination are performed in separate loops with different logic for handling empty entries. This mismatch — which Patchstack have described as a “textbook desynchronization flaw” — allows an attacker to submit two file parts for the same field, completely bypassing the extension block list and writing a PHP to a public directory.
The result is that a restricted file upload field is essentially converted into an unauthenticated remote code execution primitive. The uploaded file is stored in the path wp-content/uploads/elementor/forms/, where the <uniqid> is the output of the PHP uniqid() function. This means that the attacker can then execute their code directly through the web server, gaining complete control of the system.
See also: King Addons for Elementor: Critical vulnerability in WordPress plugin
Elementor Pro CVE-2026-32475: Technical details of the vulnerability
The vulnerability is categorized as CWE-434 (Unrestricted Upload of a File with a Dangerous Type), and affects all versions of Elementor Pro up to and including 4.2.1. The only requirement for successful exploitation is that the targeted website has at least one published Elementor that contains a Form widget with a File Upload. This is an extremely common configuration: job application forms, photo or document attachment forms, and support forms all use this feature. In fact, the “Required” option for the field is disabled by default, so no unusual configuration is required.
Security researcher Tin Pham (known as TF1T) discovered and reported the vulnerability under the Patchstack Bug Bounty Program. The report was made on July 16, 2026 , and Elementor released the patch (version 4.2.2) on August 19, 2026.Site administrators using Elementor Pro should immediately update to version 4.2.2 or later to be protected.

The broader context reveals that the Elementor is a constant target for malicious actors. In the last 12 months, similar vulnerabilities have been identified in related plugins: CVE-2026-28192 (unauthenticated arbitrary file upload in Piotnet Addons for Elementor Pro), CVE-2026-18039 (unauthenticated privilege escalation in Essential Addons for Elementor), CVE-2026-16610 (unauthenticated RCE in Admin and Site Enhancements Pro), and CVE-2026-18438 (RCE due to filename validation mismatch). This pattern shows that form builders, add-ons, and AJAX endpoints are high-value targets, as they often handle data controlled by attackers with complex validation paths.
Elementor Pro and WordPress: Wider Security Threats
The disclosure of this vulnerability coincides with the release of WordPress 7.0.4 , which addresses a separate high-severity issue ( CVE-2026-65640 , CVSS 8.8 ). This vulnerability allows remote code execution via a malicious upload of a Postscript file by a user with the Author level or higher. It affects WordPress core versions 4.7 through 7.0 . Successful exploitation requires the use of Imagick and Ghostscript on the server, as well as a user with the upload_files permission . The update changes the way WordPress handles uploaded media in ImageMagick , closing a path that could allow a logged-in author to turn a seemingly normal image into code execution on the server.
See also: WordPress Royal Elementor plugin: Fixes critical vulnerability
At the same time, security researchers have uncovered a large-scale operation called StopAndProtect that is turning thousands of compromised WordPress sites into a distributed infrastructure for malware delivery, command-and-control communications , and storage of stolen data. These developments highlight that WordPress sites are not only targets but also tools in the hands of cybercriminals, making their security an issue that concerns the entire internet.
According to The Hacker News, the Elementor Pro is particularly concerning because it doesn’t require any form of authentication. Unlike many other vulnerabilities that require at least a user account, here an attacker can exploit the flaw without having to log in to the site. This dramatically increases the number of potential attackers and makes the vulnerability particularly dangerous for sites that accept public forms.
How to protect yourself from the Elementor Pro vulnerability
The immediate action that all website administrators using Elementor Pro should take is to update to version 4.2.2 or later. This is the only complete solution to address CVE-2026-32475 . Until the update is complete, it is recommended to disable or remove public forms that contain File Upload fields to reduce the attack surface.
Additionally, administrators should check all published pages for Elementor Form widgets that accept file uploads — especially contact, support, job application, and document submission forms. Checking web server and WordPress logs for suspicious file uploads, especially PHP files or other executables in upload directories, is also critical. At the web server level, it is recommended to restrict execution in upload directories and implement whitelists of allowed file extensions and MIME types .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

If signs of abuse are detected, experts recommend assuming that successful exploitation could lead to a full site breach and immediately changing all passwords and security keys. In general, WordPress are urged to keep plugins and themes up to date, scan for unauthorized modifications that serve unexpected redirects or pop-ups, and regularly check for unknown accounts and plugins. The Elementor Pro is yet another reminder that even the most popular and trusted solutions can hide critical security flaws that require immediate remediation.
