Elementor Pro Forms file upload flaw can enable PHP code execution
Source headline: Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Intelligence Summary
A critical flaw has been disclosed in the Elementor Pro WordPress plugin. Tracked as CVE-2026-32475, it has a CVSS score of 9.0. The issue is described as unrestricted upload of a file with a dangerous type. The flaw is in the Forms module's File functionality. If exploited, it could allow unauthenticated attackers to upload a PHP file and execute code. Patch or mitigate Elementor Pro to reduce the risk of remote code execution.
Recommended Action
Check your exposure to CVE-2026-32475 (CVSS 9.0) and apply the vendor fix once available. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.