Description
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Published: 2026-09-10
Score: 9.8 Critical
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Update
AI Analysis

Impact

The Drag and Drop File Upload for Elementor Forms plugin for WordPress allows unauthenticated users to upload arbitrary files. The vulnerability is caused by the elementor_file_upload function, which uses an attacker-controlled 'type' parameter as a regular‑expression key in a MIME type allowlist. An attacker can craft a file name that is later sanitized to a PHP extension, bypassing the validation and permitting the upload of potentially executable code. Consequently, an attacker can achieve remote code execution on the WordPress site.

Affected Systems

The affected product is the Drag and Drop File Upload for Elementor Forms plugin by addonsorg. All versions up to and including 1.6.0 are vulnerable. No other WordPress components are directly impacted beyond the plugin's upload handling.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, reflecting the high impact and ease of exploitation. EPSS data is not available and the vulnerability is not listed in CISA KEV. Attackers need only send a crafted file to the upload endpoint; no authentication is required. Successful exploitation can lead to full remote code execution, giving attackers control over the affected site.

Generated by OpenCVE AI on September 10, 2026 at 03:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the plugin to the latest available version, which fixes the file‑type validation logic.
  • If an immediate update cannot be performed, temporarily disable the upload feature or restrict the plugin to known safe file types only.
  • Enable logging of all file‑upload attempts and review logs for executable extensions or suspicious activity.

Generated by OpenCVE AI on September 10, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Addonsorg
Addonsorg drag And Drop File Upload For Elementor Forms
Wordpress
Wordpress wordpress
Vendors & Products Addonsorg
Addonsorg drag And Drop File Upload For Elementor Forms
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Title Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Addonsorg Drag And Drop File Upload For Elementor Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-10T11:18:32.534Z

Reserved: 2026-07-30T06:01:04.246Z

Link: CVE-2026-18351

cve-icon Vulnrichment

Updated: 2026-09-10T11:17:00.775Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T02:16:34.180

Modified: 2026-09-10T14:39:13.757

Link: CVE-2026-18351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:47:44Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type