plugin

Drag And Drop File Upload For Elementor Forms Vulnerabilities

2 known security issues reported for the Drag And Drop File Upload For Elementor Forms WordPress plugin. Most recent disclosed Aug 26, 2025.

1 critical 1 medium

Running Drag And Drop File Upload For Elementor Forms on your site? Check whether your installed version is affected.

Scan your site free

Drag and Drop File Upload for Elementor Forms <= 1.5.3 - Unauthenticated Arbitrary File Upload

critical

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...

CVSS:
9.8
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Aug 26, 2025

CVE-2025-49387 on NVD →

Drag and Drop File Upload for Elementor Forms <= 1.4.3 - Unauthenticated Arbitrary File Deletion

medium

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the elementor_file_upload_remove() function in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to delete arbitrary fi...

CVSS:
5.3
Affected:
up to 1.4.3
Fixed in:
1.5.0
Disclosed:
May 15, 2025

CVE-2025-47492 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database