Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Summary

A critical vulnerability has been disclosed in the Elementor Pro WordPress plugin, allowing unauthenticated attackers to upload dangerous file types and execute code remotely. The flaw, tracked as CVE-2026-32475, has a CVSS score of 9.0 and affects the Forms module's file upload functionality.

IFF Assessment

FOE

This vulnerability allows attackers to execute code on affected systems, posing a significant risk to website security.

Severity

9.0 Critical

Defender Context

Defenders should prioritize patching or updating the Elementor Pro plugin to the latest version to mitigate the risk of remote code execution. This vulnerability highlights the importance of regularly scanning for and addressing plugin-specific security flaws in WordPress environments.

Read Full Story →