Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows attackers to upload executable PHP files via a crafted multipart upload, leading to remote code execution (RCE) on the server. The flaw exists in the File Upload module due to inconsistent handling of empty filename uploads between validation and processing loops. Exploitation requires a published Elementor Pro form with a File Upload field and the multiple file upload option enabled. The vulnerability affects versions before 4.2.2. A fix has been released, and administrators are advised to update and check for malicious files uploaded during the exposure period. No active exploitation has been observed in the wild so far.
AI Analysis
Technical Summary
CVE-2026-32475 is a critical remote code execution vulnerability in Elementor Pro versions prior to 4.2.2. It arises from a logic discrepancy in the File Upload module where the validation loop exits early on an empty filename upload part (UPLOAD_ERR_NO_FILE), ignoring subsequent parts, while the processing loop continues and moves files to a public directory. An attacker can exploit this by sending a multipart upload with an initial empty filename part followed by a malicious PHP payload. The payload is saved in wp-content/uploads/elementor/forms/ with a predictable filename generated by uniqid(), allowing attackers to locate and execute it via the web server's PHP interpreter. Exploitation requires the target site to have an Elementor Pro form with a File Upload field and multiple file upload enabled (disabled by default). The vulnerability was responsibly disclosed to Elementor, which released a patch shortly after discovery. Users are advised to update to version 4.2.2 or later and inspect upload directories for malicious files.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary PHP code on the web server with the privileges of the web server process. This can lead to full compromise of the affected WordPress site, including data theft, site defacement, or pivoting to other network resources. The vulnerability specifically affects sites using Elementor Pro forms with file upload fields and multiple file upload enabled. No active exploitation has been reported in the wild at this time.
Mitigation Recommendations
A patch has been released by Elementor in version 4.2.2 that fixes this vulnerability. Site administrators should update Elementor Pro to version 4.2.2 or later immediately. Additionally, administrators should inspect the wp-content/uploads/elementor/forms/ directory for any unauthorized PHP or suspicious files uploaded during the vulnerable period and remove them. Since the vulnerability requires the multiple file upload option enabled in forms (disabled by default), disabling this option can reduce exposure if immediate patching is not possible. No other action is required if the site does not use Elementor Pro forms with file upload fields.
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
Description
A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows attackers to upload executable PHP files via a crafted multipart upload, leading to remote code execution (RCE) on the server. The flaw exists in the File Upload module due to inconsistent handling of empty filename uploads between validation and processing loops. Exploitation requires a published Elementor Pro form with a File Upload field and the multiple file upload option enabled. The vulnerability affects versions before 4.2.2. A fix has been released, and administrators are advised to update and check for malicious files uploaded during the exposure period. No active exploitation has been observed in the wild so far.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-32475 is a critical remote code execution vulnerability in Elementor Pro versions prior to 4.2.2. It arises from a logic discrepancy in the File Upload module where the validation loop exits early on an empty filename upload part (UPLOAD_ERR_NO_FILE), ignoring subsequent parts, while the processing loop continues and moves files to a public directory. An attacker can exploit this by sending a multipart upload with an initial empty filename part followed by a malicious PHP payload. The payload is saved in wp-content/uploads/elementor/forms/ with a predictable filename generated by uniqid(), allowing attackers to locate and execute it via the web server's PHP interpreter. Exploitation requires the target site to have an Elementor Pro form with a File Upload field and multiple file upload enabled (disabled by default). The vulnerability was responsibly disclosed to Elementor, which released a patch shortly after discovery. Users are advised to update to version 4.2.2 or later and inspect upload directories for malicious files.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary PHP code on the web server with the privileges of the web server process. This can lead to full compromise of the affected WordPress site, including data theft, site defacement, or pivoting to other network resources. The vulnerability specifically affects sites using Elementor Pro forms with file upload fields and multiple file upload enabled. No active exploitation has been reported in the wild at this time.
Mitigation Recommendations
A patch has been released by Elementor in version 4.2.2 that fixes this vulnerability. Site administrators should update Elementor Pro to version 4.2.2 or later immediately. Additionally, administrators should inspect the wp-content/uploads/elementor/forms/ directory for any unauthorized PHP or suspicious files uploaded during the vulnerable period and remove them. Since the vulnerability requires the multiple file upload option enabled in forms (disabled by default), disabling this option can reduce exposure if immediate patching is not possible. No other action is required if the site does not use Elementor Pro forms with file upload fields.
Technical Details
- Classification
- {"confidence":0.72,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/","fetched":true,"fetchedAt":"2026-08-20T14:52:28.804Z","wordCount":874}
Threat ID: 6a8714adacd9273b49c20f81
Added to database: 08/20/2026, 14:52:29 UTC
Last enriched: 08/20/2026, 14:52:52 UTC
Last updated: 08/20/2026, 15:10:23 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.