# Elementor Pro patch addresses unauthenticated PHP-upload flaw

_Tuesday, August 18, 2026 at 8:00 PM EDT · Security · Latest · Tier 2 — Notable_

![Elementor Pro patch addresses unauthenticated PHP-upload flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G/s1700-e365/wordpress.jpg)

Researchers disclosed CVE-2026-32475, a critical Elementor Pro flaw that could let an unauthenticated attacker upload a PHP file and achieve remote code execution.

Patchstack said the Forms module handles extension validation and file movement in separate loops, allowing two file parts with an empty entry to bypass the extension blocklist. The issue affects versions through 4.2.1 when a published Elementor page includes a Form widget with a File Upload field.

Elementor Pro released version 4.2.2 on August 19 after the issue was reported on July 16.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html)

---
Canonical: https://techandbusiness.org/newswire/b4eUI6SqF1-_ZRlyNWYhE3
Retrieved: 2026-08-20T08:01:49.747Z
Publisher: Tech & Business (techandbusiness.org)
