{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/drag-and-drop-file-upload-for-elementor-forms--1.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:drag_and_drop_file_upload_for_elementor_forms_project:drag_and_drop_file_upload_for_elementor_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18351"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=72B56444-A6B0-5501-BBC8-ADA512B55501\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Drag and Drop File Upload for Elementor Forms (\u003c= 1.6.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","wordpress","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Drag and Drop File Upload for Elementor Forms WordPress plugin, version 1.6.0 and earlier, contains a critical arbitrary file upload vulnerability tracked as CVE-2026-18351. The vulnerability exists within the 'is_file_type_valid()' function, which improperly handles the 'type' parameter during file uploads. Specifically, the function uses this attacker-controlled parameter as a regex key when checking against MIME type allowlists. By crafting a request that influences this logic, an unauthenticated attacker can bypass existing file type restrictions. The 'sanitize_file_name()' function subsequently normalizes the filename, potentially converting a manipulated input into a executable PHP script. If successfully exploited, this flaw allows for unauthenticated remote code execution on the underlying WordPress server. Defenders should identify instances of this plugin in their environment and ensure they are patched beyond version 1.6.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify sites running the vulnerable Drag and Drop File Upload for Elementor Forms plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the 'elementor_file_upload' function endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious payload into the 'type' parameter to subvert the 'is_file_type_valid()' regex validation logic.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a file with a double extension or normalized name that bypasses the MIME type allowlist.\u003c/li\u003e\n\u003cli\u003eThe plugin's 'sanitize_file_name()' function normalizes the malicious filename into an executable PHP file.\u003c/li\u003e\n\u003cli\u003eThe web server saves the attacker-supplied PHP file to a publicly accessible directory.\u003c/li\u003e\n\u003cli\u003eAttacker requests the uploaded PHP file via the web browser to trigger remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18351 enables unauthenticated remote code execution. This can lead to full site compromise, data exfiltration, installation of webshells for persistence, and further lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Drag and Drop File Upload for Elementor Forms plugin to the latest available version beyond 1.6.0.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for HTTP POST requests to the 'elementor_file_upload' endpoint containing irregular 'type' parameters or attempts to upload .php, .phtml, or .php5 files.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect and block requests containing suspicious MIME type strings or file upload attempts from unauthorized or non-standard sources.\u003c/li\u003e\n\u003cli\u003eUse file integrity monitoring to detect the creation of new, unexpected files in plugin-associated upload directories.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-11T04:27:56Z","date_published":"2026-09-10T03:03:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-drag-and-drop-file-upload-rce/","summary":"An arbitrary file upload vulnerability in the Drag and Drop File Upload for Elementor Forms WordPress plugin allows unauthenticated attackers to execute arbitrary code via MIME type validation bypass.","title":"Unauthenticated Remote Code Execution in Drag and Drop File Upload for Elementor Forms","url":"https://feed.craftedsignal.io/briefs/2026-09-drag-and-drop-file-upload-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Drag and Drop File Upload for Elementor Forms (\u003c= 1.6.0)","version":"https://jsonfeed.org/version/1.1"}