Critical Vulnerability in Drag and Drop File Upload for Elementor Forms Plugin
A critical vulnerability (CVE-2026-18351, CVSS 9.8) exists in the Drag and Drop File Upload for Elementor Forms plugin for WordPress, allowing unauthenticated attackers to upload arbitrary files, including potentially executable files, leading to remote code execution. All versions up to and including 1.6.0 are affected. Immediate action is required to mitigate this vulnerability.