Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical Elementor Pro Remote Code Execution Vulnerability (CVE-2026-32475)

A critical vulnerability (CVE-2026-32475) has been identified in the Elementor Pro WordPress plugin that could allow attackers to upload malicious executable files and potentially execute arbitrary code on affected WordPress servers.
 
Affected Systems:
  • Elementor Pro WordPress plugin: version 4.2.1 and earlier.
 
Security Risks
 
Successful exploitation could allow an unauthenticated attacker to upload and execute malicious PHP files on the affected server, potentially resulting in remote code execution, unauthorized access, data compromise, website takeover, or further compromise of the hosting environment.
 
For a complete list of other recently disclosed WordPress plugin vulnerabilities and available patches, please refer to a WordPress vulnerability database.


Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Upgrade, as soon as possible, to the latest supported version to maintain security and continue receiving technical support and patches.
 
The released software version for upgrade is:
  • Elementor Pro WordPress plugin: Upgrade to version 4.2.2 or above
 
2. Ensure you have the latest backup that can be easily restored before applying any updates or patches.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.

References

25 August 2026

© 2026 National Cyber Security Authority