Update to the latest patched version of Elementor Pro immediately. Apply all available security updates from the Elementor development team. Monitor official Elementor security advisories for further details and confirmation of patches.
Quick answers
What is CVE-2026-32475?
Update to the latest patched version of Elementor Pro immediately. Apply all available security updates from the Elementor development team. Monitor official Elementor security advisories for further details and confirmation of patches.
How severe is CVE-2026-32475?
critical, CVSS 9
Is CVE-2026-32475 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-32475 be mitigated?
Update to the latest patched version of Elementor Pro immediately. Apply all available security updates from the Elementor development team. Monitor official Elementor security advisories for further details and confirmation of patches.
CVSS
9
Vendor
Elementor
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Elementor Pro WordPress plugin
Mitigation
Update to the latest patched version of Elementor Pro immediately. Apply all available security updates from the Elementor development team. Monitor official Elementor security advisories for further details and confirmation of patches.
A critical vulnerability in the Elementor Pro plugin for WordPress, tracked as CVE-2026-32475, is being actively exploited in attacks that deliver webshell payloads and enable arbitrary command execution. Elementor has released a patch; users are urged to update immediately.
Researchers have detailed a critical vulnerability in the Elementor Pro WordPress plugin tracked as CVE-2026-32475. The flaw stems from unrestricted file upload functionality within the Forms module, potentially allowing unauthenticated attackers to upload PHP files and execute arbitrary code. The vulnerability carries a CVSS score of 9.0 and affects the global WordPress ecosystem using the Elementor Pro plugin.