9

CVE-2026-32475

Medienbericht

WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability

Elementor Pro <= 4.2.1 - Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.

This issue affects Elementor Pro: from n/a through 4.2.1.
Mögliche Gegenmaßnahme
Elementor Website Builder Pro: Update to version 4.2.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElementor
Produkt Elementor Pro
Default Statusunaffected
Version <= 4.2.1
Version n/a
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Elementor Website Builder Pro
Version *-4.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
audit@patchstack.com 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
21.08.2026 12:52
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.08.2026 16:50
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.08.2026 08:20
https://patchstack.com/database/wordpress/plugin/elementor-pro/vulnerability/wordpress-elementor-pro-plugin-4-2-1-arbitrary-file-upload-vulnerability?_s_id=cve
https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09
Third Party Advisory