CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4744

As cited

Copy frozen at (site build).

vulnerabilities

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Researchers disclosed a critical vulnerability (CVE-2026-32475) in Elementor Pro's Forms module that allows unauthenticated attackers to upload and execute arbitrary PHP files. The flaw scores 9.0 CVSS and stems from insufficient validation of file uploads.

Why it matters: WordPress site administrators using Elementor Pro face immediate risk of remote code execution and full site compromise; patching or disabling the Forms module should be prioritized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Researchers disclosed a critical vulnerability (CVE-2026-32475) in Elementor Pro's Forms module that allows unauthenticated attackers to upload and execute arbitrary PHP files. The flaw scores 9.0 CVSS and stems from insufficient validation of file uploads.

Why it matters: WordPress site administrators using Elementor Pro face immediate risk of remote code execution and full site compromise; patching or disabling the Forms module should be prioritized.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary