By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Elementor Pro Vulnerability Allows Unauthenticated Code Execution

Cybersecurity researchers have disclosed details of a critical flaw within the Elementor Pro WordPress plugin, a widely used page builder that empowers users to create custom website designs without extensive coding knowledge. This vulnerability, officially tracked as CVE-2026-32475, has been assigned a severity score of 9.0 out of a possible 10.0 on the Common Vulnerability Scoring System (CVSS), classifying it as critical. The flaw is described as an instance of unrestricted file upload, specifically allowing the upload of files with dangerous types. This means that an attacker could potentially upload a PHP file, which is a server-side scripting language commonly used for web development, to a WordPress site running the vulnerable plugin.
The vulnerability resides within the Forms module of Elementor Pro. This module enables website owners to create and manage forms for various purposes, such as contact forms, registration forms, and feedback forms. A key feature of form builders is often the ability to allow users to upload files, such as images or documents. However, in this case, the validation mechanism for uploaded files is insufficient, permitting the upload of executable scripts like PHP files. Once a malicious PHP file is uploaded to the server, an unauthenticated attacker can then trigger its execution. This execution could lead to a range of malicious activities, including the theft of sensitive data, the defacement of the website, or the installation of further malware.
Exploitation of this vulnerability does not require any prior authentication, meaning an attacker does not need to log in to the WordPress site or possess any special privileges. This significantly broadens the attack surface, as any website using the affected version of Elementor Pro becomes a potential target. The ability to execute arbitrary code on the server grants attackers a high level of control over the compromised website and its underlying infrastructure. The implications are severe, potentially impacting the integrity and availability of the website, as well as the privacy of user data collected through the site's forms.
Elementor Pro is a premium add-on for the Elementor page builder, offering advanced features and design capabilities for WordPress websites. Elementor itself is one of the most popular WordPress page builder plugins globally, with millions of active installations. The Pro version is utilized by many businesses and individuals seeking to create sophisticated and professional-looking websites. The disclosure of this critical vulnerability raises significant concerns for the security of the vast number of websites that rely on Elementor Pro for their design and functionality. Users are strongly advised to update their Elementor Pro plugin to the latest version as soon as it becomes available to mitigate this risk. The specific version range affected by CVE-2026-32475 has not been detailed in the initial disclosure, but prompt patching is the standard recommendation for critical vulnerabilities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.