logo

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

ID: d67a7084-cb62-556e-9ce4-b1b94b63df7f

STIX ID: report--d67a7084-cb62-556e-9ce4-b1b94b63df7f

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed a critical RCE vulnerability in the Elementor Pro WordPress plugin (CVE-2026-32475, CVSS 9.0) where a flaw in the Forms module's File Upload field allows unauthenticated attackers to bypass extension checks and write PHP files to wp-content/uploads/elementor/forms/, enabling remote code execution; a patch (v4.2.2) was released August 19, 2026. The report also notes a recent WordPress core RCE fix (CVE-2026-65640) and highlights a large-scale operation dubbed 'StopAndProtect' abusing compromised WordPress sites for malware delivery and C2, advising users to update, scan for unauthorized changes, and audit accounts and plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.