Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-32475: Elementor Pro Forms Unauthenticated Arbitrary File Upload to RCE Lab & PoC

github.com | vulnerability | Critical | CVE-2026-32475 | #bug-bounty | #rce | #wordpress | #red-team | #poc | #file-upload | #cve-2026-32475 | #elementor

Summary

A Docker lab and PoC for CVE-2026-32475: an unauthenticated file-upload flaw in Elementor Pro Forms (≤4.2.1) where a loop desync bypasses extension blocklists, plus uniqid() filename recovery for RCE.

Why it matters

Highlights a critical loop desync vulnerability in form upload processing, demonstrating how multipart handling flaws can bypass extension blocklists and achieve unauthenticated RCE on WordPress targets.
Vendor
Elementor
Product
Elementor Pro
Affected versions
<= 4.2.1
CVSS
9.8
Published
Collected

original ↗

Related coverage

back