Security4 distinct publishers3 min readPublished Updated
CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Patchstack has disclosed CVE-2026-32475, a critical flaw in the Elementor Pro WordPress plugin rated 9.0 out of 10.0 on CVSS and classed as unrestricted upload of a file with a dangerous type [1]. Every version up to and including 4.2.1 is affected, and the fix landed in 4.2.2 on August 19 after the report went to Elementor on July 16, 2026 [4][5].
The mechanism is a validation-and-action split, not a missing check. According to Patchstack, the extension check and the file-move step in the Forms module's File Upload field run in two separate loops that handle empty file entries differently [2]. "By submitting two file parts for the same field, an unauthenticated attacker skips the extension blocklist entirely and writes a PHP file into a public directory," the company said [3]. The write lands at wp-content/uploads/elementor/forms/ under a name produced by PHP's uniqid() function, with a .php extension [7]. No login, no privilege, no user interaction on the victim side.
The precondition is the part that should decide your patch window. Patchstack says the only requirement is that the site has at least one published Elementor page with a Form widget containing a File Upload field [6]. It called that "an extremely common, everyday configuration," citing job-application forms, attach-a-photo/ID/receipt forms and support-ticket attachments, and noted that the field's "Required" toggle defaults to off, so no hardened or unusual setting is needed [8]. The source material does not put a number on installs, so treat exposure as a question about your own page inventory rather than a headline figure: if marketing shipped a careers form, you are in scope. Tin Pham, also known as TF1T, is credited with the find under the Patchstack Bug Bounty Program [9].
It arrives on top of a core-level problem. A little over a week earlier [17], WordPress shipped 7.0.4 for CVE-2026-65640, CVSS 8.8, remote code execution via a malicious Postscript file uploaded by an Author-level user or higher, affecting core 4.7 through 7.0 [10]. That one needs two things to be true: Imagick and Ghostscript in use on the server, and an attacker holding the upload_files capability [11]. Patchstack says the update changes how WordPress hands uploaded media to ImageMagick and closes the path from an ordinary-looking image upload to code execution [12], and argues the privilege bar is low on multi-author publications, membership sites and client sites with contributors or loose registration [13].
Thirty-four days passed between report and patch on the Elementor issue [16], which is the window in which someone else could have found the same two loops.
What to watch: whether exploitation shows up against the uploads/elementor/forms path, and whether either bug feeds StopAndProtect, the operation Patchstack ties to thousands of compromised WordPress sites repurposed for malware delivery, command-and-control and storage of stolen data [14]. The stated hygiene remains unglamorous: patch, scan for unauthorised modifications serving unexpected redirects or pop-ups, and audit for unknown accounts and plugins [15].
Ranked by verification strength, evidence, and original report placement.
Patchstack said the only precondition for an attack is that the target site has at least one published Elementor page containing a Form widget with a File Upload field.
Patchstack said the configuration is "an extremely common, everyday configuration", citing job-application forms, 'attach a photo/ID/receipt' forms and support-ticket attachments, and noted the field's 'Required' toggle being off is its default state, so no hardened or unusual setting is needed.
Researchers disclosed a critical flaw in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, with a CVSS score of 9.0 out of 10.0, described as unrestricted upload of a file with a dangerous type and capable of leading to remote code execution.
Patchstack said the flaw lives in the Forms module's File Upload field, where the extension check and the file-move step run in two separate loops with different handling of empty file entries.
Patchstack: "By submitting two file parts for the same field, an unauthenticated attacker skips the extension blocklist entirely and writes a PHP file into a public directory."
The vulnerability impacts all versions of Elementor Pro prior to and including version 4.2.1.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor advisory, no independent corroboration
The technical record is specific and checkable in form: two CVE identifiers with CVSS scores, exact affected version ranges, a named root cause, the written file path, a named reporting researcher, and dated report and patch events. But every substantive detail traces to one Patchstack advisory relayed by one publisher, with no second outlet, no vendor statement from Elementor, no patch diff and no exploitation telemetry in the cluster.
Fixes shipped, exposure and uptake unquantified
There is verifiable supply-side adoption: Elementor Pro 4.2.2 and WordPress core 7.0.4 both exist as dated releases closing the two issues. What is absent is any demand-side measure: no install-base numbers, no share of sites running a published Form widget with a File Upload field, no patch-adoption rate, and no confirmed exploitation of CVE-2026-32475. The prevalence of the vulnerable configuration is only a qualitative vendor characterization.
Severity framing runs slightly ahead of verification
The headline severity is consistent with the reported CVSS 9.0 and unauthenticated precondition, so the gap is small. It is positive rather than zero because the practical-risk framing rests on unquantified vendor language ('extremely common, everyday configuration', a 'genuinely realistic threat'), because no exploitation in the wild is evidenced, and because the StopAndProtect network is placed adjacent to the CVEs without any stated causal link, which invites a connection the reporting does not support.
Disclosing vendor is also the bounty operator and a commercial beneficiary
Patchstack is a WordPress security company that both operates the bug bounty program that produced the finding and supplies the prevalence and realistic-threat framing that the article reproduces at length, including on the adjacent core CVE it did not report. That is a visible commercial interest in maximal perceived urgency. It is not scored higher because the underlying artifacts are independently checkable identifiers, versions and dates, and the publisher is a trade outlet with no disclosed stake.
Precise but uncorroborated single-publisher record
Confidence is moderate: the identifiers, version boundaries, dates and named reporter are unusually specific for a fresh disclosure, and the derived 34-day report-to-patch interval follows directly from the stated dates. It is held below the midpoint band because the cluster has one publisher and one originating vendor, no Elementor confirmation, no exploitation or uptake data, and one claim in the ledger that the sources cannot substantiate at all.
security
Attackers started dropping webshells through Elementor Pro forms on patch day1 distinct publisher
security
Five critical WordPress flaws hand attackers full site takeover1 distinct publisher
invest
Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit2 distinct publishers
security
Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told5 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · August 20, 2026
orca.security
1 article · August 20, 2026
scworld.com
1 article · August 20, 2026
thehackernews.com
2 articles · August 20, 2026