Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
News Source : Internet
News Summary
- Researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin.
- The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.
- It has been described as a case of unrestricted upload of a file with a dangerous type.
- The only precondition required to pull off an attack is that the target site has at least one published Elementor page containing a Form widget with a File Upload field.
- The findings also coincide with the discovery of a large-scale operation dubbed StopAndProtect.
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.
Never miss a story from us, subscribe to our newsletter