Critical File Upload Vulnerability in Elementor Pro
Elementor Pro through 4.2.1 has an unrestricted file upload flaw (CVSS 9.0) enabling attackers to plant webshells and run commands on WordPress servers.
- Vendor
- Elementor
- Product
- Elementor Pro
- CVSS
- 9.0
- EPSS (exploit probability)
- 2.4%
- Status
- exploited-in-wild
- Published
CVE-2026-32475 is an unrestricted file upload vulnerability in Elementor Pro, the premium page builder plugin for WordPress. NVD categorizes the issue as “Unrestricted Upload of File with Dangerous Type” and assigns it a CVSS 9.0 (critical) score.
Versions through 4.2.1 are affected. The fix is in version 4.2.2. Active exploitation delivering webshell payloads was confirmed in September 2026. If you’re running any version of Elementor Pro at or below 4.2.1, update immediately: the plugin dashboard or a direct download from Elementor’s site will get you there.
