CVE-2026-18351
Deferred Deferred - Pending Action

Arbitrary File Upload in Drag and Drop File Upload for Elementor Forms

Vulnerability report for CVE-2026-18351, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Wordfence

Description

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
superaddons drag_and_drop_file_upload_for_elementor_forms to 1.6.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Upload flaw in the Drag and Drop File Upload for Elementor Forms WordPress plugin. It allows unauthenticated attackers to upload executable files by bypassing file type validation through a crafted extension that gets normalized to a PHP extension. The issue stems from insufficient validation in the is_file_type_valid() function, which uses attacker-controlled input as regex keys in a MIME allowlist.

Detection Guidance

Check for unauthorized PHP files in WordPress upload directories, particularly in Elementor form upload paths. Review server logs for POST requests to /wp-admin/admin-ajax.php with file upload parameters. Inspect plugin version in WordPress admin panel under Plugins > Drag and Drop File Upload for Elementor Forms.

Impact Analysis

This vulnerability can allow attackers to upload malicious files to your WordPress site, potentially leading to remote code execution. This could compromise your website, steal data, or use your server for malicious activities. If you use this plugin, an attacker could gain full control over your site without needing authentication.

Compliance Impact

This vulnerability could lead to data breaches, exposing sensitive user data which would violate GDPR and HIPAA compliance. If exploited, it may result in unauthorized access to personal or health information, leading to legal penalties, fines, and reputational damage for organizations handling regulated data.

Mitigation Strategies

Immediately update the Drag and Drop File Upload for Elementor Forms plugin to the latest version. If an update is unavailable, disable the plugin until a patch is released. Implement file upload restrictions in WordPress by disabling PHP execution in upload directories and restricting allowed file types.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18351. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart