CVE-2025-49387 | add-ons Drag and Drop File Upload for Elementor Forms Plugin unrestricted upload (EUVD-2025-26012)
A vulnerability was found in add-ons Drag and Drop File Upload for Elementor Forms Plugin up to 1.5.3 on WordPress. It has been rated as critical. Affected is an unknown function. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2025-49387. The attack is possible to be carried out remotely. No exploit exists.