CVE-2026-10818 is an unauthenticated arbitrary file-upload vulnerability in the WPForms Pro WordPress plugin through version 1.10.1.1. In the ajax_chunk_upload_finalize function, chunk metadata and file contents are written to disk before file-type validation occurs. If validation fails, the assembled file is not deleted. An attacker can therefore cause files that may be executable to remain on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact exploit repo containing one substantive Python script, a README, and a license. The main file, CVE-2026-10818.py, is a multi-target Python exploit for CVE-2026-10818 affecting WPForms Pro on WordPress up to version 1.10.1.1. It is not a framework module; it is a standalone operational exploit with concurrency, target enumeration, result logging, and execution verification. The exploit targets an unauthenticated arbitrary file write in the WPForms chunked upload workflow. Based on the README and constants visible in code, it abuses the ordering of init, chunk, and finalize AJAX actions so that metadata and file contents are written before extension/MIME validation and not reliably cleaned up. The script then attempts to turn that file write into RCE by uploading executable extensions or polyglot content and probing resulting URLs. Repository structure is simple: README.md documents the vulnerability, workflow, and usage; LICENSE contains a restrictive custom license; CVE-2026-10818.py implements the exploit logic. The Python script imports requests/urllib3 and optionally BeautifulSoup for HTML parsing. It defines constants for the WordPress AJAX endpoint (/wp-admin/admin-ajax.php), the WPForms temporary upload directory (/wp-content/uploads/wpforms/tmp/), local output paths (Nx_hit/Nx_shell.txt and Nx_hit/Nx_vuln.txt), a regex for leaked hashed filenames, and a large FORM_PAGES list used to crawl likely upload/contact/application pages. Operationally, the exploit accepts a target list and thread count, scans targets concurrently, discovers candidate forms by crawling many common paths, validates vulnerable WPForms exposure, performs safe and executable uploads, computes predictable chunk paths from client-controlled UUID values, checks directory listings before and after uploads, extracts leaked filenames from responses, and verifies code execution using a unique marker string. It classifies targets as shell, vuln, skip, or miss. This is clearly exploit code rather than a detector because it actively uploads payloads and attempts remote execution confirmation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary-file-upload vulnerability affecting WPForms Pro versions through 1.10.1.1. The referenced upload-chunk AJAX actions and temporary upload path indicate that an unauthenticated attacker may be able to initialize and upload file chunks via WordPress's admin-ajax endpoint.
An arbitrary file upload vulnerability in the WPForms Pro plugin for WordPress that affects versions up to and including 1.10.1.1. Because validation occurs after file chunks are written to disk and failed assembled files are not deleted, unauthenticated attackers may upload executable files, potentially leading to remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.