CVE-2026-32475Active Exploitation

CRITICALCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 23 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 42 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 95 mentions across 23 observed days

What's happening

  • Active exploitation reported across 42 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 14 signals
  • Patch or workaround mentioned in 48 signals
  • Technical details provided in 81 signals
  • Disclosure: 21 classified signals
  • Peaked 21d ago at 23 mentions (2026-08-20); latest day: 1
  • 95 total mentions across 23 days

Deep dive

Activity timeline95 mentions / 23d
06121723Mentions · 2026-08-19: 1Mentions · 2026-08-20: 23Mentions · 2026-08-21: 10Mentions · 2026-08-22: 3Mentions · 2026-08-23: 2Mentions · 2026-08-24: 2Mentions · 2026-08-25: 3Mentions · 2026-08-26: 2Mentions · 2026-08-27: 2Mentions · 2026-08-28: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 3Mentions · 2026-09-03: 9Mentions · 2026-09-04: 15Mentions · 2026-09-05: 5Mentions · 2026-09-06: 3Mentions · 2026-09-07: 3Mentions · 2026-09-08: 1Mentions · 2026-09-09: 1Mentions · 2026-09-13: 2Mentions · 2026-09-14: 1Mentions · 2026-09-21: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-20: 3PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-25: 2PoC Mentioned / Linked · 2026-09-02: 1PoC Mentioned / Linked · 2026-09-03: 1PoC Mentioned / Linked · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-05: 1PoC Mentioned / Linked · 2026-09-07: 1PoC Mentioned / Linked · 2026-09-21: 1Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-21: 2Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-09-04: 1Exploit Tool / Code · 2026-09-05: 1Exploit Tool / Code · 2026-09-07: 1Exploit Tool / Code · 2026-09-21: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-09-02: 2Active Exploitation · 2026-09-03: 9Active Exploitation · 2026-09-04: 14Active Exploitation · 2026-09-05: 4Active Exploitation · 2026-09-06: 3Active Exploitation · 2026-09-07: 3Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-13: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 11Patch / Workaround · 2026-08-21: 4Patch / Workaround · 2026-08-22: 2Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-26: 2Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-02: 2Patch / Workaround · 2026-09-03: 3Patch / Workaround · 2026-09-04: 8Patch / Workaround · 2026-09-05: 1Patch / Workaround · 2026-09-06: 1Patch / Workaround · 2026-09-07: 2Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-13: 2Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 22Technical Details · 2026-08-21: 9Technical Details · 2026-08-22: 3Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 3Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 2Technical Details · 2026-08-28: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-02: 2Technical Details · 2026-09-03: 7Technical Details · 2026-09-04: 11Technical Details · 2026-09-05: 4Technical Details · 2026-09-06: 2Technical Details · 2026-09-07: 2Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-13: 2Technical Details · 2026-09-14: 1Technical Details · 2026-09-21: 1Technical Details · 2026-09-25: 108-1908-2108-2308-2508-2709-0109-0309-0509-0709-0909-1409-25
Signal classification6 categories
Active Exploitation
3941.1%
Patch
2425.3%
Disclosure
2122.1%
PoC
66.3%
General
33.2%
Exploit
22.1%
Referenced assets58 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-191
Patch1
2026-08-2023
Active Exploitation1Disclosure11General1Patch9PoC1
2026-08-2110
Disclosure3Exploit1General1Patch4PoC1
2026-08-223
Disclosure2Patch1
2026-08-232
Disclosure1Patch1
2026-08-242
Patch2
2026-08-253
Disclosure2PoC1
2026-08-262
Patch2
2026-08-272
Disclosure2
2026-08-281
Patch1
2026-09-011
Patch1
2026-09-023
Active Exploitation2General1
2026-09-039
Active Exploitation9
2026-09-0415
Active Exploitation14PoC1
2026-09-055
Active Exploitation4PoC1
2026-09-063
Active Exploitation3
2026-09-073
Active Exploitation2Exploit1
2026-09-081
Active Exploitation1
2026-09-091
Patch1
2026-09-132
Active Exploitation1Patch1
2026-09-141
Active Exploitation1
2026-09-211
PoC1
2026-09-251
Active Exploitation1
Full discourse20 posts
  • absholi7ly@absholi7ly
    PoC

    Poc CVE-2026-32475 Elementor Pro Unauthenticated File Upload to RCE #wordpress #rec #elementor https://t.co/3bEXjrhtO5

    Post summary

    The tweet shares a proof‑of‑concept for CVE‑2026‑32475, highlighting an unauthenticated file‑upload vulnerability in Elementor Pro that can lead to remote code execution.

    425216610511.8K
    308 followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ Unauthenticated attackers could turn Elementor Pro uploads into RCE. CVE-2026-32475 lets an attacker skip the file-extension blocklist and upload PHP when a published Form widget has a File Upload field. Elementor fixed it in 4.2.2. Read: https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html

    Post summary

    The post discloses that CVE-2026-32475 enables remote code execution through a file‑upload flaw in Elementor Pro, but the vendor has addressed the issue in version 4.2.2.

    53611213844.2K
    2.4M followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Vulnerabilidad crítica en Elementor Pro permite el control total de sitios WordPress Se ha detectado la explotación activa de una vulnerabilidad crítica (CVE-2026-32475) en el plugin Elementor Pro https://blog.elhacker.net/2026/09/vulnerabilidad-critica-en-elementor-pro.html

    Post summary

    The text reports that CVE-2026-32475 in Elementor Pro is being actively exploited, granting full control over WordPress sites.

    033157287.0K
    142.2K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    RCE PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync) https://github.com/dinosn/cve-2026-32475-elementor-pro-lab/

    Post summary

    The tweet announces a proof‑of‑concept showing remote code execution through an unauthenticated file upload flaw in Elementor Pro Forms, providing a GitHub link to the PoC code.

    010047435.8K
    161.9K followersView on X
  • CERT@certlv
    Patch

    ⚠️ Brīdinājums! Konstatēta kritiska ievainojamība Elementor Pro spraudnī (CVE-2026-32475)! Aicinām WordPress vietņu uzturētājus nekavējoties atjaunināt Elementor Pro uz jaunāko pieejamo versiju - ietekmētas visas versijas līdz 4.2.1 (ieskaitot). Vairāk: https://cert.lv/lv/2026/08/kritiska-ievainojamiba-wordpress-spraudni-elementor-pro-cve-2026-32475 https://t.co/thKAdSBrTF

    Post summary

    The tweet announces a critical vulnerability in Elementor Pro (CVE-2026-32475) and urges users to promptly update to the latest version as the recommended mitigation.

    026038511.6K
    5.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-32475 - critical 🚨 Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler > Elementor Pro plugin for WordPress in versions <=4.2.1 is vulnerable to unauthenticat... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-32475 @pdnuclei #Nuc...

    Post summary

    The tweet announces CVE‑2026‑32475, a critical unauthenticated arbitrary file upload vulnerability affecting Elementor Pro versions ≤4.2.1, but it does not provide a PoC, exploit, or mitigation details.

    15027111.7K
    1.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Elementor Pro <= 4.2.1 etkileyen CVE-2026-32475 RCE açığı için PoC yayınlandı. PoC: https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

    Post summary

    A PoC for the RCE vulnerability CVE‑2026‑32475 in Elementor Pro (≤4.2.1) has been published with a public GitHub link.

    01023122.7K
    2.4K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-32475 Vendor: Elementor Product: Elementor Pro Description: Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. Link: https://github.com/boreas37/cve-2026-32475-poc #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-32475 in Elementor Pro was published, demonstrating an unrestricted file‑upload flaw that permits malicious files.

    0502621.3K
    3.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Elementor Pro'da kritik RCE açığı WordPress için kullanılan Elementor Pro eklentisinde, kimlik doğrulaması gerektirmeden uzaktan kod çalıştırmaya yol açabilecek kritik bir güvenlik açığı keşfedildi. CVE-2026-32475 olarak takip edilen ve CVSS 9.0 skoruna sahip açık, Elementor Forms bileşenindeki File Upload alanında bulunuyor. Saldırgan, özel hazırlanmış bir multipart/form-data isteğiyle dosya uzantısı kontrolünü atlatıp sunucuya PHP dosyası yükleyebiliyor. Dosya daha sonra herkese açık bir dizine yazıldığından, uygun sunucu yapılandırmasında PHP kodunun çalıştırılması Remote Code Execution (RCE) ile sonuçlanabiliyor. Üstelik saldırı için WordPress hesabı gerekmiyor. Hedef sitede yalnızca yayınlanmış bir Elementor Form ve File Upload alanının bulunması yeterli. Etkilenen sürümler: Elementor Pro ≤ 4.2.1 🔴 Çözüm: Elementor Pro 4.2.2 veya üzeri sürüme güncelleyin.

    Post summary

    The post announces a critical authentication‑less RCE in Elementor Pro (CVE‑2026‑32475), detailing the exploit vector, affected versions, and advising an upgrade to patch the vulnerability.

    03115124.4K
    2.4K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-32475 is an unauthenticated arbitrary file upload flaw in Elementor Pro, affecting versions 4.2.1 and earlier. The vulnerability can allow attackers to bypass file-type restrictions and upload PHP files, potentially leading to remote code execution and complete WordPress site compromise. With 6M+ active installations, this could put a massive number of WordPress sites at risk. 🔴 Update Elementor Pro immediately. #WordPress #Elementor #CVE #RCE #CyberSecurity #WebSecurity #Infosec

    Post summary

    CVE-2026-32475 is an unauthenticated arbitrary file upload vulnerability in Elementor Pro that enables remote code execution; users are urged to update immediately.

    0401974.5K
    1.6K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    ⚠️ #WordPress : une faille critique dans Elementor Pro 🕵️ Aucun compte, aucune interaction avec un administrateur. Il suffit que le site publie un formulaire Elementor avec un champ permettant de charger un fichier. https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/

    Post summary

    The post announces a critical, non‑authenticated RCE in Elementor Pro, noting that a site can exploit the flaw simply by publishing a file‑upload form. No PoC, exploit code, patch, or evidence of current active exploitation is referenced.

    0638812.5K
    11.7K followersView on X
  • Mr.Niko@_MrNiko
    Exploit

    🚨 CVE-2026-32475 Elementor Pro ≤4.2.1 unauth upload → RCE empty first array part kills validation(), process_field() still moves the .php Wordfence blocked 190k+ attempts. PoC: https://github.com/Boreas37/CVE-2026-32475-PoC credit Tin Pham / Patchstack #BugBounty #VulnerabilityResearch #InfoSec

    Post summary

    An unauthenticated file‑upload flaw in Elementor Pro allows remote code execution; a PoC has been shared and Wordfence reports over 190k attempted exploits, indicating significant active exploitation.

    000157720
    1.5K followersView on X
  • Vigilant - WordPress Security Solution (100% Free)@WP_Vigilant
    Active Exploitation

    WordPress Security Notice! Elementor (plugin) - Critical Remote Code Execution (RCE) vulnerability tracked as CVE-2026-32475 (https://www.scworld.com/brief/critical-vulnerability-in-elementor-pro-exploited-for-rce-attacks) Fixed in v4.3.2 https://wordpress.org/plugins/elementor/

    Post summary

    The post reports a critical Elementor RCE CVE with a fixed version and a URL indicating exploitation in RCE attacks, making active exploitation the primary takeaway.

    141411.3K
    46 followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    🚨 CVE-2026-32475: Elementor Pro RCE under active exploitation 🔹 Affects v4.2.1 and earlier 🔹 Exploited same-day as patch release 🔹 File Upload forms = highest risk Patch to 4.2.2+ now. Learn more: https://hubs.la/Q04wKZf-0 #Elementor #RCE #CyberSecurity

    Post summary

    CVE-2026-32475, an RCE in Elementor Pro affecting v4.2.1 and earlier, is actively exploited—particularly through file upload forms—and a patch is available in v4.2.2+.

    000731.7K
    7.1K followersView on X
  • The CyberSec Guru@thecybersecguru
    Active Exploitation

    🚨 440,000+ exploit attempts. Two WordPress plugins. Full RCE. Attackers are actively targeting: 🔴 Super Forms — CVE-2026-14894 (9.8) 🔴 Elementor Pro — CVE-2026-32475 (9.0/9.8) The flaws allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable sites. Patch. Scan. Don't assume you're safe just because you updated. Full technical breakdown 👇 https://thecybersecguru.com/news/wordpress-super-forms-elementor-pro-rce-cve-2026-14894-cve-2026-32475/ #Infosec #WordPress

    Post summary

    The post highlights widespread real‑world exploitation of two WordPress plugins through RCE, urging immediate patching and scanning.

    00052340
    1.6K followersView on X
  • SecurityWeek@SecurityWeek
    Active Exploitation

    Popular Elementor Pro #WordPress Plugin Vulnerability Exploited to Hack Sites (CVE-2026-32475) - https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/

    Post summary

    CVE-2026-32475 affects the Elementor Pro WordPress plugin and is currently being exploited in the wild to compromise sites. No PoC, exploit code, patch, or detailed technical info is provided in the snippet.

    010414.2K
    229.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers. #ElementorPro #WordPressSecurity #CVE202632475 #CyberAttack #Malware https://securityexpress.info/elementor-pro-cve-2026-32475-exploited-site-takeovers/

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-32475 to upload PHP files unauthenticated and seize WordPress sites.

    00032552
    13.0K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Elementor Pro CVE-2026-32475 is being exploited after the August 19 patch. The flaw can let unauthenticated attackers upload PHP via the Form widget, leading to remote code execution and full site compromise. #ElementorPro #CVE202632475 #WordPress https://www.hendryadrian.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/

    Post summary

    The text confirms that CVE-2026-32475 is actively exploited in the wild, with attackers able to upload PHP scripts via the Form widget to achieve remote code execution, and notes a patch was issued on August 19.

    00130425
    4.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover. #ElementorPro #CVE202632475 #WordPress #Cybersecurity #RCE https://securityonline.info/elementor-pro-vulnerability/ https://t.co/KXe85TUp9I

    Post summary

    The post confirms that CVE-2026-32475 is being actively exploited in the wild and stresses the urgency of applying the available patch to prevent site takeover.

    01021531
    13.0K followersView on X
  • Cédric Aimé Fotso@cedricaimefotso
    Disclosure

    Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/ https://t.co/Z3TUOx90KR

    Post summary

    The text is a brief announcement of CVE-2026-32475, a critical unauthenticated RCE in Elementor Pro for WordPress, with limited detail beyond the headline and links to full articles.

    001211.0K
    38 followersView on X

Explore more