CVE-2026-32475
A vulnerability exists in the Elementor Pro plugin for WordPress, affecting versions up to 4.2.1, which allows an attacker to upload files of any type without restriction. This is due to a flawed validation loop in the plugin's file upload handling, which prematurely exits the validation process for subsequent files in the same upload field. As a result, an attacker can potentially upload executable files, enabling remote code execution. The vulnerability requires a targeted site to have a published page containing an Elementor Pro Form widget with a non-required file upload field.
Based on public CVE data (MITRE/NVD).