Elementor Pro flaw let attackers plant executable files on WordPress sites
A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.

Key points
- A critical flaw in Elementor Pro, tracked as CVE-2026-32475, let attackers upload and execute their own code on affected WordPress sites.
- Every version of the paid plugin before 4.2.2 is affected, but only sites running a published form with the multiple file upload field enabled are at risk.
- Elementor's free version runs on more than 10 million active WordPress sites; only the Pro edition with that specific form option is exposed.
- Patchstack learned of the bug on July 16, the vendor prepared a fix the following day, and the patch shipped on November 5.
- No live attacks have been confirmed, but administrators should update immediately and check the uploads folder for any stray PHP files.
A critical bug in Elementor Pro let strangers upload malicious files and seize control of a site's server. It's the same class of unauthenticated file-upload attack we covered in August when the Forminator plugin exposed 600,000 sites, and it shows how often form-handling code becomes the entry point.
The flaw, CVE-2026-32475, affects every Elementor Pro release before 4.2.2. Patchstack, a security firm focused on the WordPress plugin ecosystem, disclosed it this week. BleepingComputer first reported it.
Elementor is a drag-and-drop builder for WordPress sites. The free edition has more than 10 million active installs. The paid Pro version adds form building, theme and popup builders, and e-commerce tools, and tends to run on larger commercial sites.
What went wrong?
The bug lives in the file upload feature. When a visitor submits a form, Elementor Pro validates uploaded files in one loop, then moves them in a second. Those two loops don't agree on how to handle an upload whose filename is blank.
An attacker crafts a multipart upload: first entry has an empty filename, second entry carries a PHP file. PHP is the language WordPress runs on, so a PHP file in a public folder can be executed by the server. The validation loop sees the empty first entry and exits, never checking the second. The processing loop skips the empty entry and moves the PHP file into wp-content/uploads/elementor/forms/, a publicly reachable directory. Requesting that URL makes the server run the code with the same privileges WordPress itself holds. That's full remote code execution.
Finding the uploaded file's name wasn't hard. Elementor named files using PHP's uniqid() function, which is time-based rather than random. An attacker could brute-force the timestamp; in some configurations, the form's autoresponder email handed them the exact URL.
Which sites are actually at risk?
Only Pro sites running a published Elementor form with a file upload field and the multiple file upload option turned on. That option is off by default. The vendor still recommends every Pro site update regardless.
| Item | Detail |
|---|---|
| CVE | CVE-2026-32475 |
| Affected | Elementor Pro before 4.2.2 |
| Fixed in | Elementor Pro 4.2.2 |
| Reported to vendor | July 16 |
| Patch released | November 5 |
What should site owners do now?
Update to Elementor Pro 4.2.2 or later, then inspect wp-content/uploads/elementor/forms/ for PHP files or anything unexpected. Installing the patch doesn't remove files an attacker may have already dropped, so a manual check matters.
For ordinary visitors, there's no direct action to take. If a site you use was compromised, the operator is responsible for telling you. Watch for unexpected password resets or unusual charges on WordPress-built shops.
Patchstack says no active exploitation has been observed yet. Public bugs in widely installed plugins tend to attract automated scanners within hours of disclosure, so the window between announcement and mass probing is short. That gap is the one worth watching.
Common questions
Does the free version of Elementor carry this flaw?
No. CVE-2026-32475 is present only in the paid Elementor Pro edition and only when a form with the multiple file upload option is active.
Is updating enough to secure a site?
Updating closes the hole, but Patchstack warns it won't delete anything already planted. Check the uploads directory manually after patching.



