[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPZ49nlM1znndgXPxf2fywbOtTLwP8J-QIfietYs-V2k":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"2163adf5-504b-4385-a81e-66a83fc16bba","Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code","elementor-pro-flaw-could-let-unauthenticated-attackers-upload-php-and-execute-co-b1da55","Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. \"The flaw lives in the Forms module's File","A critical vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, allows unauthenticated attackers to achieve remote code execution by uploading malicious PHP files. The flaw exists in the Forms module's File Upload field due to a discrepancy in how file extensions are validated and files are moved. This allows attackers to bypass extension checks and write PHP files to public directories, enabling code execution on affected sites running versions prior to 4.2.2.","Elementor Pro flaw allows unauthenticated attackers to upload PHP and execute code.","Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code Ravie LakshmananAug 20, 2026Vulnerability \u002F Web Security Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. \"The flaw lives in the Forms module's File Upload field, where the extension check and the file-move step run in two separate loops with different handling of empty file entries,\" Patchstack said. \"By submitting two file parts for the same field, an unauthenticated attacker skips the extension blocklist entirely and writes a PHP file into a public directory.\" This discrepancy in how it validates the file's extension and moves the uploaded file to a public directory when empty file entries are processed turns a restricted file-upload field into an unauthenticated remote code execution primitive. Successful exploitation of the flaw could allow an attacker to upload arbitrary files, including PHP scripts, that could then be used to achieve remote code execution on affected systems. The security defect impacts all versions of the plugin prior to and including version 4.2.1. The WordPress security company said the only precondition required to pull off an attack is that the target site has at least one published Elementor page containing a Form widget with a File Upload field. The uploaded file is written as \"wp-content\u002Fuploads\u002Felementor\u002Fforms\u002F\u003Cuniqid>.php,\" where \"\u003Cuniqid>\" is the output of PHP's uniqid() function. \"This is an extremely common, everyday configuration: job-application forms, 'attach a photo\u002FID\u002Freceipt' forms, and support-ticket attachments all use it,\" it noted. \"The field's 'Required' toggle being off is its default state, so no hardened or unusual setting is needed.\" Security researcher Tin Pham (aka TF1T) has been credited with discovering and reporting the flaw under the Patchstack Bug Bounty Program. After the issue was reported to Elementor Pro on July 16, 2026, a patch (version 4.2.2) was released on August 19. The release comes a little over a week after WordPress released 7.0.4 to address a high-severity security issue (CVE-2026-65640, CVSS score: 8.8) that enables remote code execution via malicious Postscript file upload by an Author-level user or higher. It affects WordPress core versions 4.7 all the way up to 7.0. However, for the attack to be successful, two conditions have to be satisfied - Imagick and Ghostscript in use on the server, given the issue is in Ghostscript's handling of certain embedded files A malicious user with the upload_files capability The update \"changes how WordPress hands your uploaded media to ImageMagick, and it closes a path that could let a logged-in author turn an ordinary-looking image upload into code execution on your server,\" Patchstack said. \"If you run a multi-author publication, a membership site, a client site with contributors, or anything with open or loosely managed registration, that bar is a lot lower than it sounds. On those sites, an Author uploading a booby-trapped 'image' is a genuinely realistic threat, not a theoretical one. If it's just you and a tightly held set of trusted editors, your exposure is smaller.\" The findings also coincide with the discovery of a large-scale operation dubbed StopAndProtect that's turning thousands of compromised WordPress websites into a distributed infrastructure for malware delivery, command-and-control communications, and the storage of stolen data. WordPress users are advised to keep their websites and plugins up-to-date, scan for unauthorized modifications that serve unexpected redirects or pop-ups, and audit them for unknown accounts and plugins. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, CMS Security, file upload, Malware, Plugin Security, remote code execution, Vulnerability, Web Security, Website Security, WordPress Security ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the SOC and Where It Falls Short at Scale Defend Against One-Click AI Memory Poisoning — Download the Cheat Sheet Benchmark Your Defenses Against 338M+ Attack Simulations — Download the Blue Report 2026","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Felementor-pro-flaw-could-let.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G\u002Fs1600\u002Fwordpress.jpg","2026-08-20T06:04:34+00:00","2026-08-20T08:00:08.526741+00:00",9,[18,21,24],{"name":19,"type":20},"Elementor Pro","product",{"name":22,"type":23},"WordPress","technology",{"name":25,"type":20},"Forms module","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":26,"icon":28,"name":29,"slug":30},null,"Vulnerabilities","vulnerabilities",[32,34,39],{"category":33},{"id":26,"icon":28,"name":29,"slug":30},{"category":35},{"id":36,"icon":28,"name":37,"slug":38},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":40},{"id":41,"icon":28,"name":42,"slug":43},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[45],{"type":46,"value":47,"context":48},"cve","CVE-2026-32475","Critical vulnerability in Elementor Pro plugin"]