logo

CVE-2026-10818: WPForms Pro Arbitrary File Upload — Unauthenticated RCE

ID: 05aaeab2-a9cf-5762-bf02-b0c5ee4362bd

STIX ID: report--05aaeab2-a9cf-5762-bf02-b0c5ee4362bd

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-07-25

Date Updated: 2026-07-26

...
...

**High-severity arbitrary file upload vulnerability in WPForms Pro (≤1.10.1.1) allows unauthenticated attackers to upload and execute PHP web shells leading to full RCE (CVE-2026-10818, CVSS 8.1).** The flaw is a time-of-write/time-of-check ordering error in ajax_chunk_upload_finalize that assembles and writes chunked uploads to disk before validating file types; the report includes IOCs (unexpected PHP files in uploads, suspicious POSTs to admin-ajax.php), affected systems, and mitigation steps (patching, auditing uploads, WAF tuning, denying script execution in upload directories).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.