Vulnerability
Published 2026-09-03
Verified 2026-09-19

Elementor Pro ≤4.2.1 form upload bypass (CVE-2026-32475); ~190k blocked attempts

BleepingComputer (3 September 2026) and Wordfence (via The Hacker News, 4 September 2026) report active exploitation of CVE-2026-32475 in Elementor Pro for WordPress. Faulty validation of file-upload arrays in Elementor Pro forms (versions 4.2.1 and earlier) lets an attacker submit an empty first array element and a malicious PHP file as the second, so later files skip validation. The payload lands under /wp-content/uploads/elementor/forms/ and can be fetched to run commands. Elementor shipped 4.2.2 on 19 August 2026. Wordfence says it blocked about 190,000 exploit attempts against this CVE (and over 250,000 against Super Forms CVE-2026-14894 in the same wave — that CVE has its own desk card). Exploitation needs a published Elementor Pro Form widget with at least one File Upload field. Patchstack disclosed the issue earlier. Upgrade Elementor Pro to 4.2.2 or later; review uploads under elementor/forms for unexpected PHP; keep WAF rules current.

Product
Elementor Pro (WordPress)
Versions
Affected ≤4.2.1; fixed in 4.2.2 (19 Aug 2026)
CVSS
9.0 / 9.8 (Wordfence/THN reporting of CVE-2026-32475; confirm vector on Wordfence/NVD)
Exploited in Australia?
unknown
Patch to
Elementor Pro 4.2.2+; audit /wp-content/uploads/elementor/forms/; ensure Form File Upload fields are intentional

Primary: BleepingComputer (3 Sep 2026) · Vendor: Elementor (vendor site; fixed in Pro 4.2.2 per reporting) · CVE: CVE-2026-32475, CVE-2026-14894 · The Hacker News (4 Sep 2026; Wordfence ~190k Elementor attempts)

vulnerabilities cloud