TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/Elementor Pro Patches a Critical File Upload Bug That Enabled Remote Code Execution
News

Elementor Pro Patches a Critical File Upload Bug That Enabled Remote Code Execution

A logic mismatch between two validation loops in Elementor Pro's Forms module let unauthenticated attackers upload PHP files to WordPress sites. Elementor patched the critical flaw in version 4.2.2.

August 19, 2026 4 Min Read
66

Elementor released Elementor Pro version 4.2.2 on August 19, patching a critical vulnerability that let an unauthenticated attacker upload a working PHP file to any WordPress site running the plugin’s Forms widget with a File Upload field enabled. Patchstack disclosed the flaw the same day the patch shipped. It is tracked as CVE-2026-32475 and classified as CWE-434, unrestricted upload of a file with a dangerous type. Patchstack rated it 9.0 out of 10 on the CVSS 3.1 scale, a score Patchstack assigned itself, since NIST’s own National Vulnerability Database entry confirms NIST has not yet published an independent assessment.

Table Of Content

  • Two Loops That Disagree About an Empty File
  • Finding the File Without Much Guessing
  • A Five-Week Gap Between Report and Patch
  • What Site Owners Should Do

Elementor Pro is the paid extension of Elementor, one of the most widely used WordPress page builders. The free core plugin lists more than 10 million active installs on WordPress.org, but Elementor Pro itself is sold and distributed directly from elementor.com as a downloadable zip file rather than through the WordPress.org plugin directory, so it carries no equivalent public install counter. The vulnerable component is the Forms widget’s File Upload field, a feature site owners commonly add to contact, job-application, and support-ticket forms so visitors can attach documents.

Two Loops That Disagree About an Empty File

According to Patchstack’s technical writeup, the bug lives in modules/forms/fields/upload.php. When a form is submitted, one method, validation(), checks each uploaded file’s extension against an allowed list and a hardcoded blocklist that explicitly rejects .php and other executable extensions. A separate method, process_field(), later moves each file that passed validation into a public uploads directory. Both methods loop over the same submitted files, but they treat an empty file entry, an upload part with no filename, which PHP reports as UPLOAD_ERR_NO_FILE, differently. The validation() method exits the entire function the moment it hits an empty, non-required entry, so it never checks any file listed after it. The process_field() method simply skips that one empty entry and keeps moving every file that follows.

Patchstack found that submitting two file parts for the same upload field, an empty one first and a .php file second, lets the second file skip the extension check in validation() entirely while still reaching process_field(), which writes it into wp-content/uploads/elementor/forms/ without checking it again. The blocklist itself is sound and would normally catch a PHP upload. It simply never runs against the file that matters.

Finding the File Without Much Guessing

Because the vulnerable form sits on a site’s public front end, exploitation needs no WordPress account and no user interaction beyond submitting a form. The uploaded file is saved under a name generated by PHP’s uniqid() function, 13 hexadecimal characters that encode the Unix timestamp and microsecond of the request rather than anything random. Patchstack describes two ways an attacker can recover that filename without much brute-forcing. The server’s own Date response header hands over the eight-character timestamp portion directly, leaving only the five-character microsecond portion to narrow down, and that narrows further once an attacker records the moment just before and after the exploit request. The easier route needs no brute-forcing at all: Elementor Pro’s default form-notification template renders every submitted field, including the uploaded file’s URL, and forms with an autoresponder action enabled, common on the same job-application and support-ticket forms that carry file uploads, email that confirmation straight back to whatever address the attacker typed into the form.

A Five-Week Gap Between Report and Patch

Patchstack’s published timeline shows researcher Tin Pham, who uses the handle TF1T, reported the vulnerability to Patchstack, which confirmed it, notified Elementor, and assigned the CVE on July 16. Elementor prepared a patch the next day, and Patchstack confirmed on August 3 that the vendor’s fix actually resolved the issue. Elementor shipped that fix in version 4.2.2 on August 19, the same day Patchstack published its advisory. Elementor’s own 4.2.2 changelog credits the release with “improved code security enforcement” in the Form widget, without naming the CVE directly. Patchstack says the fix brings the two loops into agreement about what an empty file entry means and adds a second extension check directly inside process_field(), immediately before a file is moved, so the blocklist now guards the actual write rather than only the validation pass a crafted request could skip around.

What Site Owners Should Do

Patchstack published its full technical writeup, including the vulnerable code and the exact upload path, on the same day the patch went live, so site owners running Elementor Pro 4.2.1 or earlier should update to 4.2.2 promptly rather than treat this as routine plugin maintenance. Because Elementor Pro does not ship through the WordPress.org directory, keeping it current depends on an active Elementor license connected under Elementor, then License in the WordPress dashboard, so site owners should confirm both their license status and their installed version number directly rather than assume a routine update notice will catch it. Patchstack notes that because the vulnerability is unauthenticated and can leave a file behind on disk, updating closes the hole but does not undo an attempt that already succeeded. Sites that ran a vulnerable version with a public File Upload form should review wp-content/uploads/elementor/forms/ for anything that is not one of the document or image types their own forms actually accept, in particular any file ending in .php.

Tags:

CVE-2026-32475ElementorPlugin VulnerabilitiesRemote Code ExecutionWordPress Security

Share

Close-up of a refreshable Braille display connected beneath a computer keyboard, showing raised dot patterns used by blind screen reader users
Previous Post

How to Find and Fix WCAG 2.2 Accessibility Bugs With axe-core and Playwright

A weathered wooden ship's steering wheel with brass fittings aboard the historic tall ship Star of India in San Diego
Next Post

Kyverno Turns Kubernetes Policy From a Security Gate Into a Platform Primitive

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026