CVE-2026-10818
WordPress · WPForms Pro
The WPForms Pro plugin for WordPress is vulnerable to an arbitrary file upload flaw, allowing unauthenticated attackers to upload malicious files to the server.
Executive summary
A critical arbitrary file upload vulnerability in the WPForms Pro plugin for WordPress allows unauthenticated attackers to achieve remote code execution.
Vulnerability
This vulnerability is an unrestricted file upload flaw (CWE-434). It allows an unauthenticated attacker to bypass security controls and upload malicious payloads, which could lead to full site compromise.
Business impact
Successful exploitation allows an attacker to execute arbitrary code on the underlying server. This poses a severe risk to data confidentiality, integrity, and availability, potentially leading to total site takeover and the exfiltration of sensitive customer or administrative data. Given the CVSS score of 8.1, this represents a high-severity risk that requires immediate attention.
Remediation
Immediate Action: Update the WPForms Pro plugin to version 2.0.0 or later immediately to apply the patch.
Proactive Monitoring: Monitor server access logs for suspicious file upload activity or requests targeting plugin directories.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized file uploads and execution of scripts in upload directories.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in our curated sources.
Analyst recommendation
The severity of this flaw necessitates immediate action. Administrators must prioritize updating the WPForms Pro plugin to the latest version to prevent potential remote code execution and full site compromise.