Elementor Pro, rtMedia & Mailgun: Several Critical Security Vulnerabilities (CVE-2026-32475, CVE-2026-66592, CVE-2026-78003)

This text was generated using artificial intelligence (AI).Update August 20, 2026: In addition, CVE-2026-66592 (CVSS 9.3) has been reported—an unauthenticated SQL injection vulnerability in the rtMedia for WordPress, BuddyPress, and bbPress plugin up to and including version 4.7.11. See below for details.

Update August 22, 2026: In addition, CVE-2026-78003 (CVSS 9.8) has been disclosed—a server-side request forgery (SSRF) vulnerability via path traversal in the WordPress plugin “Mailgun for WordPress” through version 2.2.0. See below for details.

For the WordPress plugin Elementor Pro On August 19, 2026, the vulnerability was CVE-2026-32475 Published. It applies to Elementor Pro through and including Version 4.2.1. Patchstack describes an unauthenticated file upload in the Forms module that allows a PHP file to be uploaded and code to be executed. The vulnerability was discovered by Tin Pham (aka TF1T) as part of the Patchstack bug bounty program.

The reported CVSS score is 9.0. In terms of content, this involves an uncontrolled upload of files of a dangerous type, i.e., the vulnerability class CWE-434. The timeline in the advisory lists July 16, 2026, as the filing date; the corrected version was published a little over a month later.

Are my systems affected? Check now →