What happened
A security weakness in The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all is being tracked as CVE-2026-18351. The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1 6 0 via the elementor_file_upload function.
The important point is that running an affected version of The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all creates exposure, while an actual compromise still depends on whether the attacker can reach the trigger conditions described above. The disclosed vulnerability affects The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all, and organizations should first determine whether that technology exists in their environment.
Asset inventory should establish where The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all is deployed before severity is translated into organizational risk. Teams should verify whether Forms are enabled in each affected The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all deployment rather than assuming every installation has the same exposure.
CVE-2026-18351 currently carries a CRITICAL 9 8 severity signal in the retained vulnerability data. The Drag and Drop File Upload for Elementor Forms plugin for WordPress as an affected or pre-fix version boundary that should be checked against deployed releases. The vulnerable path involves Forms, narrowing the investigation to deployments where those components or identities are in use.
Remediation validation should confirm that the vulnerable Forms path no longer accepts the reported unsafe condition after the fix or mitigation is applied. The affected versions identified in the advisory are up to, and including, 1.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-18351 and validate the affected path after remediation.
What is not yet confirmed
- So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.