Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-32475 [Critical]

Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-32475.

Vendor
Elementor
Product
Elementor Pro
Affected versions
<= 4.2.1
CVSS
9.8
Coverage Span
2026-09-05
Reports
1 related reports

Associated Reports & Timeline

1.
github.com | vulnerability | Critical | | original ↗ | #bug-bounty | #rce | #wordpress | #red-team
A Docker lab and PoC for CVE-2026-32475: an unauthenticated file-upload flaw in Elementor Pro Forms (≤4.2.1) where a loop desync bypasses extension blocklists, plus uniqid() filename recovery for RCE.
Why it matters: Highlights a critical loop desync vulnerability in form upload processing, demonstrating how multipart handling flaws can bypass extension blocklists and achieve unauthenticated RCE on WordPress targets.