PT-2026-79306 · WordPress · Drag/Drop Multiple File Upload – Contact Form 7

·

CVE-2026-18781

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drag and Drop Multiple File Upload for Contact Form 7 versions prior to 1.3.9.9
Description An issue exists where the plugin fails to validate the final name of an uploaded file after stripping characters from it. This allows unauthenticated users to bypass file type restrictions and execute arbitrary code on the server.
Recommendations Update Drag and Drop Multiple File Upload for Contact Form 7 to version 1.3.9.9 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18781

Affected Products

Drag/Drop Multiple File Upload – Contact Form 7