Skip to main content
CyberSingle-sourceHighFeatured
7.5

Elementor Pro Arbitrary File Upload Flaw (CVE-2026-32475) Actively Exploited

A critical arbitrary file upload vulnerability (CVE-2026-32475, CVSS 9.8) in the Elementor Pro WordPress plugin is being actively exploited to compromise websites. The flaw resides in the form submission handler, allowing unauthenticated attackers to upload malicious files, likely leading to remote code execution. This poses a significant risk to the large installed base of Elementor Pro users, potentially enabling mass website takeovers and supply-chain attacks.

SecurityWeek4 days agoengCredibility 51%View source

Score Breakdown

Mosaic Score7.5
Confidence0.7
Significance0.8
Source credibility0.5
Source

Related signals

5 found