Arbitrary File Upload Vulnerability in WPForms Pro Plugin by WordPress
CVE-2026-10818

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 July 2026

What is CVE-2026-10818?

The WPForms Pro plugin allows attackers to exploit a vulnerability that permits arbitrary file uploads. This occurs because the plugin performs file type validation after the file has already been uploaded to the server. As a result, attackers can upload unauthorized executable files, potentially leading to remote code execution. The vulnerability affects all versions of WPForms Pro up to and including 1.10.1.1, compromising the security of systems using this plugin.

Affected Version(s)

WPForms Pro 0 <= 1.10.1.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lhking
.