THREAT OPS › Threat News › Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
<p>On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in <a href="https://elementor.com/pro/" rel="noopener" target="_blank">Elementor Pro</a>, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vul
MITRE ATT&CK techniques
Indicators of compromise
- 8ec93bb7e5ec96ab4636699e413382c9md5
- 4ecc8b71d0984f421844d12e862a7638md5
- CVE-2026-32475cve
- https://elementor.com/pro/url
- https://www.cve.org/CVERecord?id=CVE-2026-32475url
- www.gravatar.comdomain