SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-32475

CRITICAL · CVSS 9 EPSS 2.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Elementor Pro versions up to 4.2.1 are vulnerable to an unrestricted file upload flaw, allowing attackers to upload malicious files that could compromise the web application. This critical vulnerability poses a significant risk, as it can lead to unauthorized access and potential exploitation of the underlying server. Organizations using affected versions of Elementor Pro should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-32475
Severity
CRITICAL
CVSS
9
EPSS
2.37%

Original NVD Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.