9
CVE-2026-32475
- EPSS 0.42%
- Veröffentlicht 19.08.2026 17:24:55
- Zuletzt bearbeitet 20.08.2026 12:48:31
- CVE-Watchlists
- Unerledigt
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
Elementor Pro <= 4.2.1 - Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
Mögliche Gegenmaßnahme
Elementor Website Builder Pro: Update to version 4.2.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElementor
≫
Produkt
Elementor Pro
Default Statusunaffected
Version <=
4.2.1
Version
n/a
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Elementor Website Builder Pro
Version
*-4.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.35 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://patchstack.com/database/wordpress/plugin/elementor-pro/vulnerability/wordpress-elementor-pro-plugin-4-2-1-arbitrary-file-upload-vulnerability?_s_id=cve
https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09