Arbitrary File Upload Vulnerability in WPForms Pro Plugin by WordPress
CVE-2026-10818
8.1HIGH
What is CVE-2026-10818?
The WPForms Pro plugin allows attackers to exploit a vulnerability that permits arbitrary file uploads. This occurs because the plugin performs file type validation after the file has already been uploaded to the server. As a result, attackers can upload unauthorized executable files, potentially leading to remote code execution. The vulnerability affects all versions of WPForms Pro up to and including 1.10.1.1, compromising the security of systems using this plugin.
Affected Version(s)
WPForms Pro 0 <= 1.10.1.1