What it is
CVE-2026-32475 is an unauthenticated vulnerability affecting Elementor Elementor Pro. Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue...
Vulnerability report
Elementor Pro Arbitrary File Access
Elementor / Elementor Pro · n/a to <= 4.2.1
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-32475 is an unauthenticated vulnerability affecting Elementor Elementor Pro. Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is high. Also confirmed by third-party sources.
Who is affected?
Elementor / Elementor Pro n/a to <= 4.2.1.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
This issue affects Elementor Pro: from n/a through 4.2.1.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Wordfence
Independent exploitation attestation added to the Previdian record.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Wordfence First | 2026-09-02 15:07 UTC |
| BleepingComputer | 2026-09-03 14:52 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Nuclei template detected 28 Aug 2026.
View Nuclei template (opens in new tab)No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-32475.yaml | 28 Aug 2026 |
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
2.4%
Recent mention · BleepingComputer
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Read full advisoryRecent mention · BleepingComputer
Critical Elementor Pro flaw exploited to take over WordPress sitesBleepingComputer · 03 Sep 2026
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Recent mention · Wordfence
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro PluginWordfence · 02 Sep 2026
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The post Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin appeared first on Wordfence.
Recent mention · TheHackerNews
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute CodeTheHackerNews · 20 Aug 2026
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-08-27 22:36:44 UTC · 0 stars · AI assessment 90%
github · Created 2026-08-25 01:20:49 UTC · 1 stars · AI assessment 90%
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
nuclei · Created Unknown
Timeline
Exploitation attested by an external source
High-confidence, third-party attested exploitation
Scanner coverage available
Public proof-of-concept code published
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-32475
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-32475",
"confidence": "High",
"cvss_score": 9.0,
"cvss_estimated": false,
"epss_score": 0.02374,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}