{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wpforms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-10818"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPForms Pro plugin for WordPress \u003c= 1.10.1.1"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","arbitrary-file-upload","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WPForms"],"content_html":"\u003cp\u003eThe WPForms Pro plugin for WordPress, specifically all versions up to and including 1.10.1.1, contains a critical arbitrary file upload vulnerability tracked as CVE-2026-10818. This flaw resides within the \u003ccode\u003eajax_chunk_upload_finalize\u003c/code\u003e function, where file type validation occurs \u003cem\u003eafter\u003c/em\u003e chunk metadata and file contents have already been written to the server's disk. Compounding the issue, the plugin fails to delete these assembled files even when validation ultimately fails. This design defect permits unauthenticated attackers to upload potentially executable files, such as PHP web shells, to the WordPress installation. Successful exploitation can lead to full remote code execution on the underlying web server, allowing threat actors to gain control of the compromised system, exfiltrate sensitive data, or further compromise the network.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a crafted HTTP POST request to the WordPress site.\u003c/li\u003e\n\u003cli\u003eThe request targets the \u003ccode\u003eadmin-ajax.php\u003c/code\u003e endpoint, specifically invoking the \u003ccode\u003eajax_chunk_upload_finalize\u003c/code\u003e function of the WPForms Pro plugin, including a malicious file payload (e.g., a PHP web shell) and chunk metadata.\u003c/li\u003e\n\u003cli\u003eDue to the vulnerability (CVE-2026-10818), the plugin processes and writes the malicious file content to a temporary location on disk \u003cem\u003ebefore\u003c/em\u003e performing any file type validation.\u003c/li\u003e\n\u003cli\u003eThe plugin then attempts file type validation against the uploaded content.\u003c/li\u003e\n\u003cli\u003eThis validation subsequently fails because the uploaded file is an executable script (e.g., \u003ccode\u003e.php\u003c/code\u003e), not an allowed file type.\u003c/li\u003e\n\u003cli\u003eCritically, despite the validation failure, the plugin does not delete the temporarily assembled malicious file from the web server's disk, leaving it accessible.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the storage location of the uploaded malicious file (e.g., \u003ccode\u003eshell.php\u003c/code\u003e) and accesses it directly via a subsequent HTTP GET request.\u003c/li\u003e\n\u003cli\u003eExecuting the uploaded web shell achieves Remote Code Execution (RCE) on the compromised web server, allowing the attacker to run arbitrary commands.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-10818 grants unauthenticated attackers remote code execution capabilities on the affected WordPress server. This means an attacker can completely compromise the web server, leading to data breaches, website defacement, arbitrary data modification or deletion, and potentially using the compromised server as a pivot point for further attacks into the internal network. The total number of affected WordPress sites running WPForms Pro is currently unknown, but given the plugin's popularity, a significant number of installations could be at risk if not patched promptly.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-10818 immediately by updating the WPForms Pro plugin to version 1.10.1.2 or higher on all WordPress installations.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-10818 Exploitation - WPForms Pro Arbitrary File Upload Attempt\u0026quot; to your SIEM to identify attempts to exploit this vulnerability against the \u003ccode\u003eajax_chunk_upload_finalize\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e with \u003ccode\u003eaction=wpforms_pro_ajax_chunk_upload_finalize\u003c/code\u003e followed by subsequent GET requests to newly created PHP, JSP, ASPX, or other executable files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-25T07:18:55Z","date_published":"2026-07-25T07:18:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wpforms-pro-arbitrary-file-upload/","summary":"The WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.","title":"WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-wpforms-pro-arbitrary-file-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - WPForms","version":"https://jsonfeed.org/version/1.1"}