securityonline.info 8/21/2026, 9:31:59 AM · external

Critical CVE-2026-32475 Flaw Hits 6 Million WordPress Sites

Critical CVE-2026-32475 Flaw Hits 6 Million WordPress Sites
Developing story vulnerability 2 articles tracked
CVE-2026-32475 puts Elementor Pro at risk of file upload attacks
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content details a critical vulnerability, CVE-2026-32475, in the Elementor Pro WordPress plugin, which allows unauthenticated arbitrary file uploads, potentially leading to complete site compromise. With a CVSS score of 9.8, the flaw affects approximately 6 million installations of Elementor Pro up to version 4.2.1. Exploitation can occur without requiring user authentication, enabling attackers to run malicious PHP files.

A patch has been released in version 4.2.2, and users are strongly advised to update immediately. No active exploitation has been confirmed yet, but the vulnerability is deemed highly critical due to its widespread impact.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline