TechNewsReel
Live

Critical RCE Vulnerability Hits Elementor Pro WordPress Plugin

A flaw in the Forms module allows unauthenticated attackers to upload malicious PHP files and seize server control.

TechNewsReel Newsroom · August 20, 2026

A critical security vulnerability in the Elementor Pro WordPress plugin has left thousands of websites open to full server compromise. The flaw allows unauthenticated attackers to bypass security filters and execute arbitrary code on affected systems.

Tracked as CVE-2026-32475, the vulnerability carries a CVSS score of 9.0, designating it as critical. According to reports from Patchstack and PT Security, the issue stems from an unrestricted file upload vulnerability within the plugin's Forms module. Specifically, a discrepancy in how two separate loops handle empty file entries allows malicious PHP files to slip past the validator's blocklist. Once uploaded, these files enable remote code execution (RCE), granting attackers the ability to run arbitrary commands directly on the web server.

The Elementor Ecosystem

Elementor is one of the most widely adopted drag-and-drop website builders for the WordPress platform. While the base version is common, the Pro edition provides advanced widgets, including the Forms module used by site owners to collect user data and documents. Because these forms are typically public-facing to allow visitor submissions, the vulnerability is particularly severe; it requires no user account, administrative privileges, or prior authentication to exploit.

Industry Implications

Given Elementor's massive install base, the potential for widespread exploitation is significant. RCE is regarded as the most dangerous class of vulnerability because it provides a direct path to total system takeover. Attackers can leverage this access to steal sensitive database information, deface public-facing pages, or use the compromised server as a pivot point to launch further attacks deeper into a corporate network.

Remediation and Next Steps

Security researchers have confirmed that the vulnerability affects all versions of Elementor Pro prior to 4.2.2. The flaw has been addressed in the latest release, and administrators are urged to update to Elementor Pro version 4.2.2 or later immediately to close the gap. Site owners should verify their current version and ensure that all public-facing forms are secured. While no widespread exploitation has been detailed in the initial briefs, the critical nature of the CVSS score suggests that patching should be treated as a priority for all WordPress administrators using the Pro toolkit.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.