Critical RCE in Elementor Pro (CVE‑2026‑32475) Enables Unauthenticated PHP Upload
What It Is — A critical remote‑code‑execution vulnerability in the Elementor Pro WordPress plugin’s Forms module allows unauthenticated attackers to upload arbitrary PHP files. The flaw is tracked as CVE‑2026‑32475.
Exploitability — CVSS 9.0 (Critical). Public proof‑of‑concept code exists, and exploitation requires only a crafted HTTP request to the vulnerable endpoint.
Affected Products — Elementor Pro plugin (all versions prior to the vendor’s 3.12.1 patch) for WordPress sites.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Vulnerability Management) mandates documented detection, remediation, and audit‑ready evidence for third‑party components.
- Continuous control monitoring of software‑supply‑chain risk demonstrates due diligence to auditors and enterprise buyers.
- Maintaining an auditable trail of patch deployment and configuration hardening feeds the Verisq Trust Center evidence set required for SOC 2 assessments.
Recommended Actions
- Inventory every site running Elementor Pro and verify the installed version.
- Apply the vendor‑released patch (≥ 3.12.1) immediately.
- Enforce strict file‑type validation and disable arbitrary file uploads where not needed.
- Log and monitor upload endpoints for anomalous activity; retain logs for audit purposes.
- Map the remediation to SOC 2 control CC6.1 and capture the evidence in your compliance repository.
Source: The Hacker News