CVE-2026-32475 is an unauthenticated arbitrary file upload to RCE in Elementor Pro (<= 4. 2. 1, fixed in 4.

Source: [Dev.to](https://dev.to/stanleya/cve-2026-32475-unauthenticated-rce-in-elementor-pro-via-file-upload-validation-bypass-5e41)

Sponsored