1 vulnerability across 1 product scored HIGH or above on September 10, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-85046 (google/chrome) โ F1: exploitable โ functional, AAS: 10.6 โ 12.6 (HIGH โ CRITICAL). Originally in 2026-09-03 bulletin.
๐ [HIGH] addonsorg/drag_and_drop_file_upload_for_elementor_forms
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:addonsorg:drag_and_drop_file_upload_for_elementor_forms:*:*:*:*:*:*:*:*(< 1.6.1)
Drag and Drop File Upload for Elementor Forms by AddonsOrg is affected by one critical vulnerability (CVE-2026-18351, CVSS 9.8) that allows unauthenticated arbitrary file upload. The flaw stems from insufficient file type validation in the upload handler, where an attacker can bypass the MIME allowlist using crafted extensions that are later normalized to executable PHP files, enabling remote code execution on the hosting server. All versions through 1.6.0 are affected.
Any organization running WordPress sites with this Elementor Forms add-on should treat this as an urgent priority, as the attack requires no authentication and can lead to full server compromise. Site administrators should update to a patched version immediately or deactivate the plugin until a fix is available, and audit web servers for any unauthorized PHP files that may have been uploaded through this vector.
- ๐ CVE-2026-18351 (CVSS 3.1: 9.8)