Skip to main content

Share story

Security

Elementor Pro patch addresses unauthenticated PHP-upload flaw

Elementor Pro patch addresses unauthenticated PHP-upload flaw Image: Primary
Researchers disclosed CVE-2026-32475, a critical Elementor Pro flaw that could let an unauthenticated attacker upload a PHP file and achieve remote code execution. Patchstack said the Forms module handles extension validation and file movement in separate loops, allowing two file parts with an empty entry to bypass the extension blocklist. The issue affects versions through 4.2.1 when a published Elementor page includes a Form widget with a File Upload field. Elementor Pro released version 4.2.2 on August 19 after the issue was reported on July 16.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Policy
Products Policy

Boeing awarded US$20-billion Navy fighter development contract

Boeing has been awarded a US$20-billion US Navy contract to develop the F/A-XX sixth-generation fighter, New Atlas reports. Boeing beat rival Northrop Grumman for the contract. The Navy needs a multirole aircraft that can operate...

Products
Products

Valley National agrees to buy Bluevine for $340M

Valley National Bancorp has agreed to acquire New Jersey-based Bluevine for $340M, CTech reports. Bluevine provides digital banking and payments services to 175K small and medium-sized businesses in the US. The acquisition would ...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...

Security
Security

FortiMail flaw faces active exploitation while fixes remain unavailable

Fortinet says attackers are exploiting CVE-2026-104286 in FortiMail, with no fixed build yet available across affected release branches. The vulnerability lets an attacker without authentication send crafted HTTP or HTTPS requests...