Impact
The Drag and Drop File Upload for Elementor Forms plugin for WordPress allows unauthenticated users to upload arbitrary files. The vulnerability is caused by the elementor_file_upload function, which uses an attacker-controlled 'type' parameter as a regular‑expression key in a MIME type allowlist. An attacker can craft a file name that is later sanitized to a PHP extension, bypassing the validation and permitting the upload of potentially executable code. Consequently, an attacker can achieve remote code execution on the WordPress site.
Affected Systems
The affected product is the Drag and Drop File Upload for Elementor Forms plugin by addonsorg. All versions up to and including 1.6.0 are vulnerable. No other WordPress components are directly impacted beyond the plugin's upload handling.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, reflecting the high impact and ease of exploitation. EPSS data is not available and the vulnerability is not listed in CISA KEV. Attackers need only send a crafted file to the upload endpoint; no authentication is required. Successful exploitation can lead to full remote code execution, giving attackers control over the affected site.
OpenCVE Enrichment