Critical Elementor Pro Flaw Lets Unauthenticated Users Upload PHP Files and Execute Code Remotely

Critical Elementor Pro Flaw Lets Unauthenticated Users Upload PHP Files and Execute Code Remotely

Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to achieve remote code execution.

The flaw, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been classified as an unrestricted upload of a file with a dangerous type. The issue resides in the Forms module's File Upload field, where the extension validation and the file-move step are executed in two separate loops that handle empty file entries differently.

According to Patchstack, by submitting two file parts for the same field, an unauthenticated attacker can bypass the extension blocklist entirely and write a PHP file into a public directory. This discrepancy in how the plugin validates the file extension and moves the uploaded file when empty entries are processed turns a restricted file-upload field into an unauthenticated remote code execution primitive.

Successful exploitation allows an attacker to upload arbitrary files, including PHP scripts, which can then be used to execute code on affected systems. The vulnerability impacts all versions of the plugin up to and including version 4.2.1.

The only precondition for an attack is that the target site has at least one published Elementor page containing a Form widget with a File Upload field. The uploaded file is written to the path "wp-content/uploads/elementor/forms/ .php", where " " is the output of PHP's uniqid() function.

Patchstack emphasized that this vulnerability is particularly dangerous because it does not require authentication and can lead to full server compromise. Users are strongly advised to update the Elementor Pro plugin to the latest version immediately.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate