[CIVN-2026-0419] Arbitrary Code Execution Vulnerability in Elementor Elementor Pro Plugin of WordPress

By Published On: August 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Arbitrary Code Execution Vulnerability in Elementor Elementor Pro Plugin of WordPress


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


WordPress Elementor Pro versions prior to 4.2.2

Overview


A vulnerability has been reported in Elementor Pro WordPress plugin which could be exploited by an attacker to upload executable files for remote code execution on the targeted system.


Target Audience:

All organizations and individuals using WordPress Plugins.


Risk Assessment:

Critical risks of unauthorized file upload and remote code execution.


Impact Assessment:

Potential for unauthorized modification of website content, and system compromise.


Description


WordPress Pro Elementor Plugin is a powerful website-building solution that makes it easy to create professional, modern, and responsive WordPress websites without coding. It offers advanced design options, customizable layouts, creative widgets, animations, and a user-friendly drag-and-drop interface.


This vulnerability exists in WordPress Elementor Pro Plugin due to File Upload module, which uses separate loops for file validation and processing that handle empty filename uploads differently. An attacker could exploit these vulnerabilities by sending a specially crafted multipart upload request.


Successful exploitation of this vulnerability could allow an attacker to upload executable files for remote code execution on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/



References


BleepingComputer

https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/


CVE Name

CVE-2026-32475




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqNpSkACgkQ3jCgcSdc

ys9TRg/+PyAeL3qh1+PC/hETbnIqC5yAWLxVB/grrbCnPpDO7ceH+TNBK9W1yzgn

dx6KY3lIHn77aDUhC3vzjvKKKPAYP+6IfbrTDmRTO4i2F4OI1zDHaabu1mbk9jW4

TfTA2HRPmrDkSd9e06TqPPtKIKk6MiGPpUqNAB7NTT9Q7oOSOdSND6felYwdTAL/

jQPLYm+ldRdMWmouVeUgWBpPKzrAs8TFAusNWmk52ANTJFE7rGPor1lv1isaJvaC

KRs3XmqZcSVwa0a+4DUzTxFzDXGrbl+iSlq51SVnIGdZaiJQ4VcVS4So65QyH9hS

0XoeUhowV6OY2tvfof5sUu/n80EC57tK2f8r+5/8aD180pPm6jCdZIpw2ns+37rx

BVhPezbt5bJUxu6i6fDBW9TFE97DHvYPHZOakUMfJqjnoO/IMTY+54j0tz1hHl1a

Qa53KNBYTMIYYfYL+ZMQTkeqHEA5QAWahQWx58Bdq0LprV9kX85G8/OnKZv0DUV0

mAcLep6dpoIn/hIWME6huht56r6+oLWcTUC3gx+McKkuVLdVOfXpgjb4tGYRtuVg

SY9a6b8KJw2O8A80nyx+mGV4bNu2ebtnjyZvROAxVEqcRtjAD0b2qlz5sDL2HhIs

4R7T1pdX4PSnUcxrbLJXhdkGTBzBoEBGrut6h/t6Wm8OZSxQHL8=

=weYx

—–END PGP SIGNATURE—–

Share this article