LIVE · cybersecurity feed
Live wire
CVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emerge
CVE-2026-32475critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

zeroday.news ·

Cybersecurity researchers have reported a critical vulnerability in the Elementor Pro WordPress plugin that could enable unauthenticated attackers to upload PHP files and achieve remote code execution. The flaw, identified as CVE-2026-32475, has been assigned a CVSS score of 9.0, indicating a high level of severity.

The reported vulnerability is characterized as an unrestricted upload of a file with a dangerous type. Specifically, the flaw is said to reside within the Forms module's File Upload widget. This component, when misconfigured or improperly secured, can allow an attacker to bypass typical file type restrictions.

In the context of a WordPress plugin, an unrestricted file upload vulnerability in a forms module means that an attacker could potentially submit a specially crafted form containing a malicious PHP file. If the server-side validation for file types is insufficient or absent, the server might accept and store this dangerous file.

Once a malicious PHP file is uploaded to the web server, an attacker could then navigate to its location and execute it. This remote code execution capability grants the attacker significant control over the compromised WordPress site, potentially allowing them to deface the site, steal data, or further compromise the server.

Mitigation for this class of vulnerability typically involves implementing robust server-side validation for all file uploads. This includes strict whitelisting of allowed file extensions, checking file headers to confirm the actual file type, and ensuring that uploaded files are stored in non-executable directories. Regular security audits and keeping all plugins and themes updated are also crucial.

The Elementor Pro plugin is a widely used page builder for WordPress, extending the platform's design and functionality capabilities. Given its extensive adoption, a critical vulnerability like this could have a broad impact on websites that have not yet applied necessary updates or mitigations.

This incident underscores the ongoing importance of secure coding practices in plugin development and the necessity for website administrators to maintain a vigilant patching schedule. Flaws in popular plugins can expose a vast number of websites to significant risks, highlighting the interconnected nature of web security.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-19478critical

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

ai

Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation

Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. As enterprise security environments continue to expand across cloud, firewalls, SASE, SD-WAN, microsegmentation, and distributed infrastructure, organizations increasingly

security

US charges 17 Iranian hackers over 31-terabyte academic data theft

The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies. The post US charges 17 Iranian hackers over 31-terabyte academic data theft appeared first on Help Net Security.

malware

AI agent suggested installing a malware package. Engineer almost took its advice

Fortunately, the company had a policy of checking source code on GitHub first

ai

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Security measures that make consumers feel most secure (Source: Experian) Deception spreads across digital ch