CVE-2026-32475: Elementor Pro Forms Unauthenticated Arbitrary File Upload to RCE Lab & PoC
github.com | vulnerability | Critical | CVE-2026-32475 | #bug-bounty | #rce | #wordpress | #red-team | #poc | #file-upload | #cve-2026-32475 | #elementor
Summary
A Docker lab and PoC for CVE-2026-32475: an unauthenticated file-upload flaw in Elementor Pro Forms (≤4.2.1) where a loop desync bypasses extension blocklists, plus uniqid() filename recovery for RCE.
Why it matters
Highlights a critical loop desync vulnerability in form upload processing, demonstrating how multipart handling flaws can bypass extension blocklists and achieve unauthenticated RCE on WordPress targets.
- Vendor
- Elementor
- Product
- Elementor Pro
- Affected versions
- <= 4.2.1
- CVSS
- 9.8
- Published
- Collected
Skip to content