Update Elementor Pro now. A critical flaw is being actively exploited in the wild, and the majority of installations are still unpatched.
What the bug is
Tracked as CVE-2026-32475 with a CVSS score of 9.8, the issue is an arbitrary file upload in the function that handles form submissions. That is about as bad as it gets: it leads to remote code execution.
Who is affected
- All Elementor Pro versions up to and including 4.2.1.
- Patched in 4.2.2, released 19 August 2026.
- Roughly two thirds of Elementor’s ~10 million installations were still running a vulnerable version as of 4 September.
The free plugin is not affected
This is a Pro-only vulnerability — it sits in form submission handling, which the free plugin does not ship. If you only run Elementor free, you are not exposed to this particular CVE. Check your version anyway.
What to do
Update to 4.2.2 or later today. If you cannot update immediately, disable Elementor Pro forms and audit wp-content/uploads for unexpected PHP files.
Source: SecurityWeek.
Leave a Reply