CVE-2026-32475 is an unauthenticated arbitrary file upload to RCE in Elementor Pro (<= 4.2.1,...

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute…

Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.