CVE-2026-10818: WPForms Pro Arbitrary File Upload — Unauthenticated RCE
ID: 05aaeab2-a9cf-5762-bf02-b0c5ee4362bd
STIX ID: report--05aaeab2-a9cf-5762-bf02-b0c5ee4362bd
Feed Name: CosmicBytez Labs
**High-severity arbitrary file upload vulnerability in WPForms Pro (≤1.10.1.1) allows unauthenticated attackers to upload and execute PHP web shells leading to full RCE (CVE-2026-10818, CVSS 8.1).** The flaw is a time-of-write/time-of-check ordering error in ajax_chunk_upload_finalize that assembles and writes chunked uploads to disk before validating file types; the report includes IOCs (unexpected PHP files in uploads, suspicious POSTs to admin-ajax.php), affected systems, and mitigation steps (patching, auditing uploads, WAF tuning, denying script execution in upload directories).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
