Critical Elementor Pro error exposes WordPress sites to RCE attacks

Critical Elementor Pro error exposes WordPress sites to RCE attacks

Critical Elementor Pro error exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files to the server for remote code execution.

The flaw, identified as CVE-2026-32475, affects Elementor Pro versions prior to 4.2.2 and is due to the file upload module using separate file validation and processing loops that handle empty file name uploads differently.

“The problem is that these two loops do not agree on what to do with an empty file entry (an upload part whose filename is empty, which PHP reports as UPLOAD_ERR_NO_FILE),” a clarifies Report from Patchstacka cybersecurity company focused on the WordPress ecosystem.

Picture

“The validation loop and the processing loop have different early exit logic for these empty entries, so a carefully crafted multi-part upload can be seen in one way by the validator and in another way by the mover.”

An attacker could exploit this behavior by creating a multi-part upload where the first entry contains an empty filename, followed by a malicious PHP payload.

This causes the validation routine to exit after checking the first part, discarding it with the error UPLOAD_ERR_NO_FILE, and never checking the second part. The processing step skips the empty entry but goes through the rest of the upload and moves the PHP to a public directory in the second part (wp-content/uploads/elementor/forms/).

Elementor Pro is the paid version of Elementor, an extremely popular drag-and-drop website builder for WordPress that offers more than 10 million active installs.

The Pro version offers advanced features such as form builder, theme and popup builder, custom code and CSS, and eCommerce tools and is generally used by higher-end platforms.

According to Patchstack, exploiting CVE-2026-32475 only requires that the target page have a published Elementor form that contains a file upload field.

The researchers say that after uploading the malicious PHP, an attacker can determine its filename in the public directory because it is created using the uniqid() function, which is not random but time-based.

An attacker could determine the name of the payload through timing brute force. In some configurations, they can receive the exact URL via an autoresponder email.

Once the attacker requests the uploaded file at this URL, the server’s PHP interpreter executes its contents, allowing arbitrary code to be executed with the web server’s permissions.

Patchstack learned about CVE-2026-32475 on July 16 from Tin Pham, the researcher who discovered it, and shared the information with the Elementor team.

The next day, the plugin developer prepared a fix, which Patchstack verified on August 3rd, and delivered it yesterday.

Elementor also notified its subscribers about the vulnerability, noting that it only “compromises websites that use an Elementor Pro form with a file upload form field and the multiple file upload option enabled (this is disabled by default).”

“Every other Elementor site is unaffected. However, we still recommend updating all sites to the latest version to reduce the likelihood of security and incompatibility issues,” the provider says.

Admins should update to the latest Elementor Pro version and check the wp-content/uploads/elementor/forms/ directory for PHP files or other unwanted files.

Patchstack notes that the update will not remove malicious files uploaded during the compromise period and recommends a thorough scan.

At this time, no cases of active exploitation in the wild have been observed.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *