cve-2026-32475

CRITICAL CVSS 9.0 nvd
Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Timeline
Published
2026-08-19
Last Modified
2026-08-20
CVSS Details
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.0 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H 2.2 6.0 audit@patchstack.com
NVD metadata
NVD status
Deferred
Source identifier
audit@patchstack.com
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 9.0,
  "datePublished": "2026-08-19T18:16:38.537",
  "dateUpdated": "2026-08-20T12:48:31.843",
  "description": "Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.\n\nThis issue affects Elementor Pro: from n/a through 4.2.1.",
  "id": "CVE-2026-32475",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Elementor Pro",
            "vendor": "Elementor",
            "versions": [
              {
                "changes": [
                  {
                    "at": "4.2.2",
                    "status": "unaffected"
                  }
                ],
                "lessThanOrEqual": "4.2.1",
                "status": "affected",
                "version": "n/a",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "audit@patchstack.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.\n\nThis issue affects Elementor Pro: from n/a through 4.2.1."
      }
    ],
    "id": "CVE-2026-32475",
    "lastModified": "2026-08-20T12:48:31.843",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.0,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 6.0,
          "source": "audit@patchstack.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-32475",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-19T19:30:01.178982Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-19T18:16:38.537",
    "references": [
      {
        "source": "audit@patchstack.com",
        "url": "https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin?_s_id=cve"
      },
      {
        "source": "audit@patchstack.com",
        "url": "https://patchstack.com/database/wordpress/plugin/elementor-pro/vulnerability/wordpress-elementor-pro-plugin-4-2-1-arbitrary-file-upload-vulnerability?_s_id=cve"
      }
    ],
    "sourceIdentifier": "audit@patchstack.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-434"
          }
        ],
        "source": "audit@patchstack.com",
        "type": "Secondary"
      }
    ]
  },
  "severity": "CRITICAL",
  "source": "nvd",
  "title": "Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files..."
}
Enrichment data
Nuclei templates
Aggregated bundle (all enrichments)
View JSON API Download JSON