WordPress security by component
WPForms Pro
Plugin description
WPForms Pro is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 25, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
wpforms-proLatest vulnerability
CVE-2026-10818: WPForms Pro chunk finalization permits unauthenticated executable uploads
WPForms Pro through 1.10.1.1 lets an unauthenticated request reach ajax_chunk_upload_finalize, where chunk metadata and contents are written to disk before the assembled file's type is validated. When validation fails, the assembled file is not removed, allowing an attacker to leave a file that may be executable by the web server and potentially obtain remote code execution. The CNA record does not disclose the request route, action name or chunk parameter names.
| Safe version |
|
||
|---|---|---|---|
| Jul 25, 2026 |
CVE-2026-10818
WPForms Pro chunk finalization permits unauthenticated executable uploads
WPForms Pro through 1.10.1.1 lets an unauthenticated request reach ajax_chunk_upload_finalize, where chunk metadata and contents are written to disk before the assembled file's type is validated. When validation fails, the assembled file is not removed, allowing an attacker to leave a file that may be executable by the web server and potentially obtain remote code execution. The CNA record does not disclose the request route, action name or chunk parameter names.
|
1.10.2 |
CVE8.1
NVDPending
|
| Nov 14, 2022 |
CVE-2022-3574
WPForms Pro: A security weakness
WPForms Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|