CVE-2026-18781 PUBLISHED

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass

Assigner: WPScan
Reserved: 04.08.2026 Published: 21.08.2026 Updated: 21.08.2026

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.

Product Status

Vendor Unknown
Product Drag and Drop Multiple File Upload for Contact Form 7
Versions Default: unaffected
  • affected from 0 to 1.3.9.9 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE