A critical vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, allows unauthenticated attackers to upload arbitrary files and achieve remote code execution on affected sites. The flaw impacts versions 4.2.1 and earlier and exists in the Forms module’s File Upload field, where file validation and file movement are handled inconsistently across separate loops. By crafting a multipart request with two file parts for the same field, an attacker can bypass extension checks and place a PHP file in the publicly accessible wp-content/uploads/elementor/forms/ directory.
The issue can be exploited when a published Elementor page includes a Form widget with a File Upload field, a configuration described as common because the field is not required by default. Researcher Tin Pham (TF1T) reported the bug through the Patchstack Bug Bounty Program, and Elementor addressed it in version 4.2.2 by aligning the loop logic and adding an extension check in the file-move path. Defenders were warned that upgrading does not remove files already uploaded through exploitation and should inspect the Elementor forms upload directory for unexpected PHP files.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request added a full Nuclei template and proof-of-concept for CVE-2026-32475, showing how Elementor Pro's form upload flow could write a PHP file despite returning a file-type rejection message. The material demonstrated retrieval and execution of the uploaded file, providing public technical exploitation details for the flaw.
Elementor Pro released version 4.2.2 to patch CVE-2026-32475, which affects versions 4.2.1 and earlier. The fix aligns validation and processing logic for file uploads and adds an extension check before moving uploaded files.
Patchstack said it verified Elementor's remediation for CVE-2026-32475 on August 3 after the developer prepared a fix following disclosure. This marked a separate coordination milestone before Elementor Pro 4.2.2 was publicly released.
Wordfence said it received a vulnerability submission for CVE-2026-32475 through its Bug Bounty Program. The report concerned an unauthenticated arbitrary file upload flaw in Elementor Pro that could lead to remote code execution.
Patchstack said it confirmed CVE-2026-32475 and disclosed the Elementor Pro arbitrary file upload vulnerability to the vendor after researcher Tin Pham (TF1T) reported it. The flaw can allow unauthenticated file upload leading to remote code execution on affected sites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceheise.de
Open sourcethehackernews.com
Open sourcecve.org
Open sourcepatchstack.com
Open sourcepatchstack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.