THE content details a critical vulnerability, CVE-2026-32475, in the Elementor Pro WordPress plugin, which allows unauthenticated arbitrary file uploads, potentially leading to complete site compromise. With a CVSS score of 9.8, the flaw affects approximately 6 million installations of Elementor Pro up to version 4.2.1. Exploitation can occur without requiring user authentication, enabling attackers to run malicious PHP files.
A patch has been released in version 4.2.2, and users are strongly advised to update immediately. No active exploitation has been confirmed yet, but the vulnerability is deemed highly critical due to its widespread impact.