Critical Vulnerability in WordPress Plugin - Elementor Pro (CVE-2026-32475)

A vulnerability has been identified in the Elementor Pro plugin allowing unrestricted file uploads, affecting all versions up to 4.2.1 inclusive. The issue stems from a faulty validation cycle—if the first file in an upload field has 'UPLOAD_ERR_NO_FILE', the validation process uses 'return' instead of 'continue'. This causes the function to terminate prematurely and skip further file extension and MIME type checks for remaining files in the same upload field. Such incomplete validation enables attackers to upload files with potentially executable content, bypassing intended file type restrictions. Depending on server configuration and uploaded file execution capabilities, this may lead to remote code execution and complete site compromise. Users are advised to update Elementor Pro to the latest version as soon as possible.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source