logo

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

ID: 18c53aee-ecfa-5047-a759-8d2e414d6ec1

STIX ID: report--18c53aee-ecfa-5047-a759-8d2e414d6ec1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Bill Toulas

...
...

A critical RCE vulnerability (CVE-2026-32475) in Elementor Pro (<4.2.2) allows attackers to craft multipart uploads that bypass validation and write a PHP payload to wp-content/uploads/elementor/forms/, enabling remote code execution if a site has a published Elementor Pro form with a File Upload field and multiple file upload enabled; a patch is available and administrators should update and inspect upload directories for rogue files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.