Vulnerability threat dossier

CVE-2026-32475

ElementorElementor Pro

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

VTP deterministic threat22.0of 100 · CVSS excluded

VTP analyst assessment

Elementor Pro malicious file upload

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence85%
Public exploitation · VTP factREPORTED

Assessment

CVE-2026-32475 affects Elementor Pro through version 4.2.1. The form-submission handler permits dangerous file uploads. SecurityWeek and The Hacker News report exploitation; the latter attributes widespread attempts to Wordfence. Public Nuclei tooling is also available.

Why it matters

  • A successful file upload could let attackers place malicious content on affected WordPress sites.
  • Reported exploitation makes remediation and review of exposed form functionality urgent.

Evidence

4 record references and 4 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The press reports are not independently confirmed in this bundle.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Elementor Pro through 4.2.1, apply the vendor remediation immediately.

AI baseline history (8)
  1. BASELINE ASSESSED
    Elementor Pro malicious file uploadgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Critical Elementor Pro unrestricted file upload with reported exploitationgpt-5.6-sol · high
  3. BASELINE ASSESSED
    Elementor Pro unauthenticated file-upload RCEgpt-5.6-sol · high
  4. BASELINE ASSESSED
    Elementor Pro unrestricted malicious-file uploadgpt-5.6-sol · high
  5. BASELINE ASSESSED
    Reported exploitation of Elementor Pro vulnerabilitygpt-5.6-sol · high
  6. BASELINE ASSESSED
    Public template with unresolved vulnerability metadatagpt-5.6-sol · high
  7. BASELINE ASSESSED
    Reported Elementor Pro file-upload RCE flawgpt-5.6-sol · high
  8. BASELINE ASSESSED
    Reported Elementor Pro unauthenticated code-execution pathgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.0 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.0283th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A proof of concept is reported; functional reliability is not established.

  2. 02

    EPSS is 0.02; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03

Claim provenance

Evidence and source independence

8publications detected
8underlying evidence chains

0 primary sources · 0 dependent secondary reports · 7 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:649d0b773fc11da690ef363e2e2968a5f555e826cd99d7a9f2d2ce3c5da9a0c3ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:d546d8ad567d11fa9adbab63b6a58be0a3c9d1bbACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:5916 Sept
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-32475.

  2. 14:5203 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 03:2328 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

05

Original publications

Source record

Nuclei Templates v10.4.9 - Release Notes

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin

CVE-2016-3714CVE-2017-7504CVE-2017-8225CVE-2018-10933CVE-2018-15708CVE-2018-3760CVE-2019-11043CVE-2019-17554CVE-2019-8942CVE-2020-10221CVE-2020-2555CVE-2020-29134CVE-2021-34429CVE-2021-43798CVE-2022-39258CVE-2023-54391CVE-2024-1708CVE-2024-52433CVE-2025-14047CVE-2025-14998CVE-2025-15403CVE-2025-29927CVE-2025-51683CVE-2025-53887CVE-2025-57231CVE-2026-0561CVE-2026-0650CVE-2026-0702CVE-2026-0743CVE-2026-0768CVE-2026-11801CVE-2026-1281CVE-2026-12898CVE-2026-18577CVE-2026-18963CVE-2026-19092CVE-2026-19632CVE-2026-2113CVE-2026-21875CVE-2026-23491CVE-2026-23536CVE-2026-23693CVE-2026-26265CVE-2026-27454CVE-2026-27960CVE-2026-28141CVE-2026-28411CVE-2026-29962CVE-2026-29963CVE-2026-30849CVE-2026-32475CVE-2026-33017CVE-2026-34234CVE-2026-41042CVE-2026-41452CVE-2026-41456CVE-2026-41679CVE-2026-41948CVE-2026-42221CVE-2026-4257CVE-2026-42596CVE-2026-42878CVE-2026-44177CVE-2026-44343CVE-2026-48558CVE-2026-53595CVE-2026-55040CVE-2026-55229CVE-2026-5524CVE-2026-5562CVE-2026-56292CVE-2026-57582CVE-2026-58123CVE-2026-58191CVE-2026-59177CVE-2026-59509CVE-2026-59726CVE-2026-60105CVE-2026-61511CVE-2026-61736CVE-2026-62382CVE-2026-65761CVE-2026-72898CVE-2026-73034CVE-2026-73570CVE-2026-7467CVE-2026-76904CVE-2026-77806CVE-2026-81199CVE-2026-81578CVE-2026-82222CVE-2026-82329CVE-2026-83548CVE-2026-8467CVE-2026-85200CVE-2026-85706CVE-2026-86206CVE-2026-86207CVE-2026-86426CVE-2026-87820CVE-2026-88062CVE-2026-9133CVE-2026-9586
Separate evidence group
Original

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek .

CVE-2026-32475
Separate evidence group
Original

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

CVE-2026-14894CVE-2026-32475
Separate evidence group
Original

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]

CVE-2026-32475
Separate evidence group
Original

Exploit tooling coverage expanded for 6 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 6 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2026-18577CVE-2026-32475CVE-2026-55040CVE-2026-73570CVE-2026-7467CVE-2026-77806
Separate evidence group
Original

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

CVE-2021-27101CVE-2023-34362CVE-2026-12143CVE-2026-13242CVE-2026-14682CVE-2026-15580CVE-2026-15748CVE-2026-15826CVE-2026-18051CVE-2026-18963CVE-2026-19478CVE-2026-19505CVE-2026-19506CVE-2026-19507CVE-2026-19508CVE-2026-19509CVE-2026-20030CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318CVE-2026-20319CVE-2026-20357CVE-2026-20358CVE-2026-20359CVE-2026-24301CVE-2026-25895CVE-2026-32475CVE-2026-40144CVE-2026-40145CVE-2026-41472CVE-2026-41473CVE-2026-47836CVE-2026-47841CVE-2026-55803CVE-2026-57580CVE-2026-59270CVE-2026-63093CVE-2026-63182CVE-2026-64849CVE-2026-65346CVE-2026-65770CVE-2026-65801CVE-2026-65816CVE-2026-65922CVE-2026-66794CVE-2026-6837CVE-2026-69106CVE-2026-69502CVE-2026-69555CVE-2026-69836CVE-2026-73570CVE-2026-74934CVE-2026-74935CVE-2026-74936CVE-2026-74949CVE-2026-75501CVE-2026-75874CVE-2026-76017CVE-2026-76034CVE-2026-76036CVE-2026-76310CVE-2026-76311CVE-2026-76312CVE-2026-76389CVE-2026-76395CVE-2026-76404
Separate evidence group
Original

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

CVE-2026-32475
Separate evidence group
Original

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

CVE-2026-32475CVE-2026-65640
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score22.0vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.47 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-434
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.