
Drag and Drop File Upload for Elementor Forms Security & Risk Analysis
wordpress.org/plugins/drag-and-drop-file-upload-for-elementor-formsAllows you to add powerful Drag & Drop or choose Multiple Files Uploading area to your Elementor Forms.
Is Drag and Drop File Upload for Elementor Forms Safe to Use in 2026?
Generally Safe
Score 94/100Drag and Drop File Upload for Elementor Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "drag-and-drop-file-upload-for-elementor-forms" v1.5.5 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to good coding practices, with all identified AJAX handlers and REST API routes (though none were found) having proper authentication and permission checks. The absence of critical taint analysis findings and the heavy reliance on prepared statements for SQL queries are also reassuring. Furthermore, nearly all output is properly escaped, and the plugin does not bundle outdated libraries.
However, the vulnerability history presents a significant concern. Two known CVEs have been recorded, including one critical vulnerability. The types of past vulnerabilities, "Unrestricted Upload of File with Dangerous Type" and "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", indicate a history of insecure handling of file uploads and directory manipulation. While currently unpatched CVEs are reported as zero, the past occurrence of critical vulnerabilities in these specific areas warrants careful consideration. The plugin's attack surface, though small and protected, is coupled with a history of exploitable flaws in sensitive functionalities.
In conclusion, while the current code demonstrates improvements in fundamental security practices like authentication and output escaping, the historical presence of critical vulnerabilities in file handling functions remains a notable weakness. Users should remain vigilant and ensure they are using the latest available versions of the plugin, as past critical vulnerabilities suggest potential for future exploits if similar issues re-emerge or are not fully mitigated. The presence of past critical issues necessitates a higher degree of caution.
Key Concerns
- History of critical unpatched CVEs
- History of medium severity CVEs
- History of critical vulnerability types
Drag and Drop File Upload for Elementor Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Drag and Drop File Upload for Elementor Forms <= 1.5.3 - Unauthenticated Arbitrary File Upload
Drag and Drop File Upload for Elementor Forms <= 1.4.3 - Unauthenticated Arbitrary File Deletion
Drag and Drop File Upload for Elementor Forms Release Timeline
Drag and Drop File Upload for Elementor Forms Code Analysis
Output Escaping
Drag and Drop File Upload for Elementor Forms Attack Surface
AJAX Handlers 5
WordPress Hooks 17
Maintenance & Trust
Drag and Drop File Upload for Elementor Forms Maintenance & Trust
Maintenance Signals
Community Trust
Drag and Drop File Upload for Elementor Forms Alternatives
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Protect Uploads
protect-uploads
Protect your uploads directory. Prevent browsing, add watermarks, disable right-click, and password-protect files. For more information, visit protect …
WP Offload Media Lite for Amazon S3, DigitalOcean Spaces, and Google Cloud Storage
amazon-s3-and-cloudfront
Copies files to Amazon S3, DigitalOcean Spaces or Google Cloud Storage as they are uploaded to the Media Library. Optionally configure Amazon CloudFro …
Drag and Drop File Upload for Elementor Forms Developer Profile
59 plugins · 26K total installs
How We Detect Drag and Drop File Upload for Elementor Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/dropzone.js/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/css/dropzone.css/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/drag-drop-file-upload.js/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/css/drag-drop-file-upload.css/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/dropzone.js/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/drag-drop-file-upload.js/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/css/dropzone.css?ver=/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/dropzone.js?ver=/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/css/drag-drop-file-upload.css?ver=/wp-content/plugins/drag-and-drop-file-upload-for-elementor-forms/includes/js/drag-drop-file-upload.js?ver=HTML / DOM Fingerprints
elementor-field-type-file_uploadsuperaddons-file-upload-wrapperdropzone-wrapperdropzone<!-- Default Template --><!-- Uploaded File --><!-- Error Message --><!-- Loading Icon -->data-file-upload-typedata-max-file-sizedata-allowed-file-typesdata-max-filesdata-dropzone-templateDropzone