Skip to main content
Back to Newswire
Security

Elementor Pro patch addresses unauthenticated PHP-upload flaw

Elementor Pro patch addresses unauthenticated PHP-upload flaw Image: Primary
Researchers disclosed CVE-2026-32475, a critical Elementor Pro flaw that could let an unauthenticated attacker upload a PHP file and achieve remote code execution. Patchstack said the Forms module handles extension validation and file movement in separate loops, allowing two file parts with an empty entry to bypass the extension blocklist. The issue affects versions through 4.2.1 when a published Elementor page includes a Form widget with a File Upload field. Elementor Pro released version 4.2.2 on August 19 after the issue was reported on July 16.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire