CVE-2026-32475 -- CVSS 9.0 Vulnerability Briefing
CVE-2026-32475 | CVSS 9.0 (Critical) | Exploit: PoC available
What Is It
CVE-2026-32475 is an unrestricted file upload vulnerability in the Elementor Pro WordPress plugin, affecting versions through 4.2.1, that may allow malicious file uploads.
Technical Detail
The flaw allows files with dangerous types to be uploaded without sufficient restriction. An attacker able to reach the affected upload functionality could upload a malicious file to the WordPress server. Depending on server configuration, file handling controls, and the uploaded file type, successful exploitation could lead to remote code execution or other compromise of the affected site.
Exploitation Status
A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed by the provided data.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updating Elementor Pro to a version later than 4.2.1 that remediates CVE-2026-32475. Until patching is complete, restrict access to WordPress administrative and file-upload functions, enforce least-privilege permissions for WordPress accounts, and ensure web server configuration prevents execution of uploaded files in writable upload directories. Review web server, WordPress, and endpoint logs for unexpected uploads, newly created executable or script files in upload paths, and suspicious requests targeting Elementor Pro upload functionality. Verify that backups are available and inspect affected sites for unauthorized files or changes after remediation.