Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ["cve", "vulnerability", "wordpress", "elementor-pro", "file-upload", "unauthenticated-arbitrary-file-upload", "webshell"] ยท confidence: high ยท severity: critical ยท affected_sectors: ["Technology"] ยท au_impact: true

CVE-2026-32475

Affected product: WordPress Elementor Pro plugin, versions 4.2.1 and earlier (6M+ installs)

Patched version: 4.2.2, released 19 August 2026

Active exploitation: Yes โ€” actively exploited in the wild; over 190,000 blocked attempts between 19 and 23 August delivering PHP webshells

Assessment

CVE-2026-32475 is a critical file-upload-array validation bypass in the Elementor Pro WordPress plugin that lets an unauthenticated attacker upload a malicious PHP file to /wp-content/uploads/elementor/forms/ and execute arbitrary commands, effectively taking over the site. Exploitation began the same day the vendor shipped 4.2.2, and Wordfence has blocked more than 190,000 attempts between 19 and 23 August, with attackers uploading webshell payloads. The vector only works on sites with a published Elementor Pro Form widget containing at least one File Upload field, a common configuration, which means the unauthenticated exposure is broadly applicable. Elementor Pro is widely deployed on Australian SMB and personal WordPress sites, so administrators should upgrade to 4.2.2 or later immediately and inspect the forms upload directory for rogue PHP files before assuming a clean state.