Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-32475 -- CVSS 9.0 Vulnerability Briefing

CVE-2026-32475 | CVSS 9.0 (Critical) | Exploit: PoC available

What Is It

CVE-2026-32475 is an unrestricted file upload vulnerability in the Elementor Pro WordPress plugin, affecting versions through 4.2.1, that may allow malicious file uploads.

Technical Detail

The flaw allows files with dangerous types to be uploaded without sufficient restriction. An attacker able to reach the affected upload functionality could upload a malicious file to the WordPress server. Depending on server configuration, file handling controls, and the uploaded file type, successful exploitation could lead to remote code execution or other compromise of the affected site.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed by the provided data.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize updating Elementor Pro to a version later than 4.2.1 that remediates CVE-2026-32475. Until patching is complete, restrict access to WordPress administrative and file-upload functions, enforce least-privilege permissions for WordPress accounts, and ensure web server configuration prevents execution of uploaded files in writable upload directories. Review web server, WordPress, and endpoint logs for unexpected uploads, newly created executable or script files in upload paths, and suspicious requests targeting Elementor Pro upload functionality. Verify that backups are available and inspect affected sites for unauthorized files or changes after remediation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →