CVE-2026-18351
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-434
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- addonsorg Drag and Drop File Upload for Elementor Forms
Weakness type
Related vulnerabilities
- CVE-2026-84063 — BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous...
- CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page
- CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173),...
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload