PT-2026-78533 · WordPress · Elementor Pro
CVE-2026-32475
·
Published
2026-08-19
·
Updated
2026-09-09
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elementor Pro versions prior to 4.2.2
Description
An unrestricted file upload flaw exists in the Form widget of Elementor Pro, potentially affecting over 6 million active installations. The issue occurs when a public form contains at least one non-required file upload field. A logic error in the
Upload::validation() function causes the validation routine to exit prematurely if the first element of a submitted file array is empty. This allows an unauthenticated attacker to bypass file extension and MIME type checks for subsequent files in the array, enabling the upload of malicious PHP webshells to the /wp-content/uploads/elementor/forms/ directory. This can lead to remote code execution (RCE) and full website takeover. Real-world exploitation began on August 19, 2026, with over 190,000 exploit attempts blocked by Wordfence. Attackers target the /wp-admin/admin-ajax.php endpoint using the elementor pro forms send form action.Recommendations
Update Elementor Pro to version 4.2.2 or later.
As a temporary mitigation, disable the Form widget or remove non-required file upload fields from public forms.
Restrict the ability of the web server to execute PHP files within the
/wp-content/uploads/elementor/forms/ directory.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elementor Pro