CVE · Critical

CVE-2026-32475 — Elementor Pro [elementor-pro] < 4.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32475 Elementor Pro [elementor-pro] < 4.2.2 Unrestricted Upload of File with Dangerous Type Critical 9.0 < 4.2.2 4.2.2 2025-06-19

CVE-2026-32475

A vulnerability exists in the Elementor Pro plugin for WordPress, affecting versions up to 4.2.1, which allows an attacker to upload files of any type without restriction. This is due to a flawed validation loop in the plugin's file upload handling, which prematurely exits the validation process for subsequent files in the same upload field. As a result, an attacker can potentially upload executable files, enabling remote code execution. The vulnerability requires a targeted site to have a published page containing an Elementor Pro Form widget with a non-required file upload field.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.