PT-2026-78533 · WordPress · Elementor Pro

CVE-2026-32475

·

Published

2026-08-19

·

Updated

2026-09-09

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elementor Pro versions prior to 4.2.2
Description An unrestricted file upload flaw exists in the Form widget of Elementor Pro, potentially affecting over 6 million active installations. The issue occurs when a public form contains at least one non-required file upload field. A logic error in the Upload::validation() function causes the validation routine to exit prematurely if the first element of a submitted file array is empty. This allows an unauthenticated attacker to bypass file extension and MIME type checks for subsequent files in the array, enabling the upload of malicious PHP webshells to the /wp-content/uploads/elementor/forms/ directory. This can lead to remote code execution (RCE) and full website takeover. Real-world exploitation began on August 19, 2026, with over 190,000 exploit attempts blocked by Wordfence. Attackers target the /wp-admin/admin-ajax.php endpoint using the elementor pro forms send form action.
Recommendations Update Elementor Pro to version 4.2.2 or later. As a temporary mitigation, disable the Form widget or remove non-required file upload fields from public forms. Restrict the ability of the web server to execute PHP files within the /wp-content/uploads/elementor/forms/ directory.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32475

Affected Products

Elementor Pro