importantSYS.SOURCE: The Hacker News• 2026-08-20T11:34:34+05:30
Critical Unauthenticated RCE Vulnerability in Elementor Pro Allows PHP File Uploads
A critical vulnerability (CVE-2026-32475) in Elementor Pro's Forms module allows unauthenticated attackers to upload PHP files and achieve remote code execution through flawed file validation. The flaw affects all versions prior to 4.2.1 and requires only a published form with a file upload field for exploitation.
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.
The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.
"The flaw lives in the Forms module's File
*** END OF TRANSMISSION ***