CRITICAL 9.8 CVE-2026-18351 Published 10 Sept 2026

WordPress Elementor Forms File Upload Bug

Worried this affects one of your servers?

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload.

This is due to insufficient file type validation in the is_file_type_valid() function, allowing unauthenticated attackers to upload files that may be executable.

This vulnerability affects all versions up to, and including, 1.6.0.

Reference: CVE-2026-18351 on NVD

← Back to Security News