All 3 CVE vulnerabilities found in Drag and Drop File Upload for Elementor Forms, with AI-generated Chinese analysis, references, and POCs.
Vendor: add-ons.org
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-18351 | Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter CWE-434 | 9.8 | Critical | 2026-09-10 |
| CVE-2025-49387 | WordPress Drag and Drop File Upload for Elementor Forms Plugin <= 1.5.3 - Arbitrary File Upload Vulnerability CWE-434 | 10.0 | Critical | 2025-08-28 |
| CVE-2025-47492 | WordPress Drag and Drop File Upload for Elementor Forms plugin <= 1.4.3 - Arbitrary File Deletion Vulnerability CWE-22 | 8.6 | High | 2025-05-23 |
All 3 known CVE vulnerabilities affecting Drag and Drop File Upload for Elementor Forms with full Chinese analysis, references, and POCs where available.