Vulnerability Management Critical vulnerability in Elementor Pro allows unauthenticated file upload and RCE August 20, 2026 Share By SC Staff A critical vulnerability in the Elementor Pro WordPress plugin, identified as CVE-2026-32475, could allow attackers to upload executable files for remote code execution on the server, according to a report by Patchstack. The flaw affects Elementor Pro versions prior to 4.2.2, stemming from an issue in the File Upload module that mishandles empty filename uploads differently during validation and processing, Bleeping Computer reports. The vulnerability arises from a discrepancy between two loops within the File Upload module: one for validation and one for processing. An attacker can exploit this by crafting a multipart upload with an empty filename in the first part, followed by a malicious PHP payload. The validation loop incorrectly dismisses the empty first part, while the processing step moves the PHP payload to a public directory (wp-content/uploads/elementor/forms/). Attackers can then determine the payload's filename, often through timing or autoresponder emails, and execute it by requesting the file's URL. This allows arbitrary code execution with the web server's privileges. Elementor has released version 4.2.2 to address the issue, and administrators are urged to update immediately and scan their sites for malicious files. While no active exploitation has been observed, websites using Elementor Pro forms with the file upload feature enabled are at risk. Source: Bleeping Computer SC Staff Related Bug Bounties Vercel offers $1 million in bounties for sandbox hacks SC Staff August 20, 2026 The two-week program challenges participants to breach an isolated sandbox environment hosted by Vercel. Patch/Configuration Management Microsoft Defender bug causing crashes resolved SC Staff August 20, 2026 The bug caused Windows Defender quick or full scans to fail, sometimes requiring the service to be restarted. Patch/Configuration Management Microsoft removes WMIC tool from Windows 11 SC Staff August 19, 2026 WMIC, a legacy command-line utility for interacting with Windows Management Instrumentation (WMI), has been progressively phased out. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds