SECURITY·중요도 9·2026. 08. 20.·The Hacker News
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
── KO ──────────────────
Elementor Pro의 취약점으로 인증 없이 PHP 파일 업로드 및 실행 가능.
Elementor Pro 워드프레스 플러그인에서 심각한 취약점이 발견되었습니다. 이 취약점은 CVE-2026-32475로 추적되며, CVSS 점수는 9.0입니다. 인증 없이 위험한 유형의 파일을 업로드하고 코드 실행을 유도할 수 있는 가능성이 있습니다. 이는 보안 전문가들에 의해 주의해야 할 사항으로 강조됩니다.
── EN ──────────────────
Vulnerability in Elementor Pro allows unauthenticated PHP file uploads and code execution.
A critical vulnerability has been discovered in the Elementor Pro WordPress plugin. This vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0. It allows unauthenticated attackers to upload dangerous file types and execute remote code. Security experts emphasize the importance of addressing this flaw.