CVE-2026-18351: Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter

Published Sep 10, 2026
·
Updated

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementorfileupload function. This is due to insufficient file type validation in the isfiletypevalid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitizefilename() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Affected Software

1 affected component
WordPress Drag and Drop File Upload for Elementor Forms<=1.6.0

Event History

Sep 10, 2026
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote attacker can exploit it; no WordPress account or user interaction is required. Exploitation targets the plugin's file-upload functionality.

2

What conditions are needed for exploitation?

The affected plugin must be installed at version 1.6.0 or earlier and its vulnerable upload handling must be reachable. An attacker can supply a crafted type parameter and filename extension to bypass file-type validation and cause the filename to be normalized to a PHP extension.

3

What is the likely impact of a successful upload?

An attacker may upload an executable file, which can lead to remote code execution. The stated impact includes complete compromise of confidentiality, integrity, and availability.

4

How can I tell whether my site is affected?

Check whether Drag and Drop File Upload for Elementor Forms is installed and whether its version is 1.6.0 or earlier. Sites running those versions should treat the plugin's elementor_file_upload functionality as vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203