Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-32475

Critical File Upload Vulnerability in Elementor Pro

Elementor Pro through 4.2.1 has an unrestricted file upload flaw (CVSS 9.0) enabling attackers to plant webshells and run commands on WordPress servers.

cat cve-2026-32475.json
Vendor
Elementor
Product
Elementor Pro
CVSS
9.0
EPSS (exploit probability)
2.4%
Status
exploited-in-wild
Published

CVE-2026-32475 is an unrestricted file upload vulnerability in Elementor Pro, the premium page builder plugin for WordPress. NVD categorizes the issue as “Unrestricted Upload of File with Dangerous Type” and assigns it a CVSS 9.0 (critical) score.

Versions through 4.2.1 are affected. The fix is in version 4.2.2. Active exploitation delivering webshell payloads was confirmed in September 2026. If you’re running any version of Elementor Pro at or below 4.2.1, update immediately: the plugin dashboard or a direct download from Elementor’s site will get you there.