CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-32475: Elementor Pro File Upload RCE

August 20, 2026

Critical vulnerability in Elementor Pro WordPress plugin allowing unauthenticated attackers to upload PHP files and execute code. CVSS 9.0. Affects versions up to 4.2.1. Patched in 4.2.2.