Two loops disagreed about empty fields — and that was an unauthenticated PHP upload on any Elementor form
2026-08-20Security
CVE-2026-32475 is a CVSS 9.0 in Elementor Pro's Forms module. Validation and file-moving run in separate loops that handle empty entries differently, so submitting two file parts for one field skips the extension blocklist entirely. All versions to 4.2.1 are affected; 4.2.2 fixes it.