CVE-2026-18781

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 07:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18781

Mitre link : CVE-2026-18781

CVE.ORG link : CVE-2026-18781


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')