๐Ÿ” CVE Alert

CVE-2025-49387

UNKNOWN 0.0

WordPress Drag and Drop File Upload for Elementor Forms Plugin <= 1.5.3 - Arbitrary File Upload Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.5.3.

CWE CWE-434
Vendor add-ons.org
Product drag and drop file upload for elementor forms
Published Aug 28, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for add-ons.org drag and drop file upload for elementor forms

Be the first to know when new unknown vulnerabilities affecting add-ons.org drag and drop file upload for elementor forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

add-ons.org / Drag and Drop File Upload for Elementor Forms
0 โ‰ค 1.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/drag-and-drop-file-upload-for-elementor-forms/vulnerability/wordpress-drag-and-drop-file-upload-for-elementor-forms-plugin-1-5-3-arbitrary-file-upload-vulnerability?_s_id=cve

Credits

Phat RiO | Patchstack Bug Bounty Program