The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 07:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-18781
Mitre link : CVE-2026-18781
CVE.ORG link : CVE-2026-18781
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
