Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Criminal probe clears Sloth World of criminal neglect in deaths of 57 animals

    August 20, 2026

    Transocean’s 16-year-old drillship lands $300M job with India’s ONGC

    August 20, 2026

    Sydney air traffic controllers have ‘grave concerns’ about collision risk after airspace redesign | Sydney airport

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Criminal probe clears Sloth World of criminal neglect in deaths of 57 animals
    • Transocean’s 16-year-old drillship lands $300M job with India’s ONGC
    • Sydney air traffic controllers have ‘grave concerns’ about collision risk after airspace redesign | Sydney airport
    • Italy’s migrant detention hubs in Albania undermine human rights, says Amnesty – POLITICO
    • Tice defends suspension of Reform UK activist over Farage criticism | Reform UK
    • A MAGA County’s Top Election Official Wants to Hire Election Denial Superstar Tina Peters
    • Critical Elementor Pro bug exposes WordPress sites to RCE attacks
    • Morning Minute: Hyperliquid Is Coming to the US
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Elementor Pro bug exposes WordPress sites to RCE attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.

    Identified as CVE-2026-32475, the flaw affects Elementor Pro versions before 4.2.2 and stems from the File Upload module, which uses separate loops for file validation and processing that handle empty filename uploads differently.

    “The problem is that these two loops disagree about what to do with an empty file entry (an upload part whose filename is blank, which PHP reports as UPLOAD_ERR_NO_FILE),” clarifies a report from Patchstack, a cybersecurity company focused on the WordPress ecosystem.

    image

    “The validation loop and the processing loop have different early-exit logic for these empty entries, so a carefully shaped multi-part upload can be seen one way by the validator and another way by the mover.”

    An attacker could exploit this behavior by crafting a multipart upload in which the first entry has an empty filename, followed by a malicious PHP payload.

    This causes the validation routine to exit after examining the first part, dismissing it with the UPLOAD_ERR_NO_FILE error and never checking the second part. The processing step skips the empty entry but goes through the rest of the upload and moves to a public directory (wp-content/uploads/elementor/forms/) the PHP in the second part.

    Elementor Pro is the paid version of Elementor, a highly popular drag-and-drop website builder for WordPress that has more than 10 million active installs.

    The Pro version adds more advanced features such as form creation, theme and popup builders, custom code and CSS, and e-commerce tools, and is generally used by higher-grade platforms.

    According to Patchstack, exploiting CVE-2026-32475 requires only that the target site have a published Elementor form containing a File Upload field.

    The researchers say that after uploading the malicious PHP, an attacker can determine its filename in the public directory because it is created using the uniqid() function, which is not random but time-based.

    An attacker could determine the name of the payload through a timing brute-force. In some configurations, they can obtain its exact URL through an autoresponder email.

    Once the attacker requests the uploaded file at that URL, the server’s PHP interpreter executes its contents, allowing arbitrary code to run with the privileges of the web server.

    Patchstack learned of CVE-2026-32475 on July 16 from Tin Pham, the researcher who discovered it, and shared the information with the Elementor team.

    The next day, the plugin developer prepared a fix, which Patchstack verified on August 3, and delivered it yesterday.

    Elementor has also notified its subscribers of the vulnerability, noting that it puts at risk only “websites that use an Elementor Pro Form with an upload file form field, and the multiple file upload option enabled (it is disabled by default).”

    “Every other Elementor site is unaffected, however we still recommend all sites update to the latest version to reduce the likelihood of security and incompatibility issues,” the vendor says.

    Administrators should update to the latest Elementor Pro release and check the ‘wp-content/uploads/elementor/forms/’ directory for PHP files or other rogue files.

    Patchstack notes that updating does not remove malicious files uploaded during the exposure period and recommends a thorough examination.

    At this time, no cases of active exploitation have been observed in the wild.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks Bug critical Elementor exposes Pro RCE sites WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Agentic AI Presents New Insider Threat Model for Orgs

    Citrix urges admins to patch new NetScaler flaws as soon as possible

    CISA warns of hackers exploiting critical MLflow vulnerability

    OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

    Critical Zimbra RCE flaw now actively exploited in attacks

    Hackers compromise 14,500 Dahua web cameras in 35-day campaign

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Criminal probe clears Sloth World of criminal neglect in deaths of 57 animals

    August 20, 2026

    Transocean’s 16-year-old drillship lands $300M job with India’s ONGC

    August 20, 2026

    Sydney air traffic controllers have ‘grave concerns’ about collision risk after airspace redesign | Sydney airport

    August 20, 2026

    Italy’s migrant detention hubs in Albania undermine human rights, says Amnesty – POLITICO

    August 20, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Criminal probe clears Sloth World of criminal neglect in deaths of 57 animals

    August 20, 2026

    Transocean’s 16-year-old drillship lands $300M job with India’s ONGC

    August 20, 2026

    Sydney air traffic controllers have ‘grave concerns’ about collision risk after airspace redesign | Sydney airport

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.