Vulnerability intelligence
CVE-2026-32475
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
CVSS Score
9
Critical
EPSS — Exploit Probability
1.7%
Riskier than 77% of all CVEs · checked 2026-10-02
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
4 articles across 3 outlets · first covered Aug 21, 2026 · latest Sep 5, 2026
Coverage timeline
-
Elementor Pro Flaw Exploited to Upload PHP Backdoors on Websiteswww.securityweek.com · Sep 5, 2026
-
Attackers Exploit Two WordPress Flaws to Deploy Web Shellsthehackernews.com · Sep 4, 2026
-
CVE-2026-32475: Elementor Pro RCE Exploited in the Wildsecurityonline.info · Sep 2, 2026
-
Critical CVE-2026-32475 Flaw Hits 6 Million WordPress Sitessecurityonline.info · Aug 21, 2026