PT-2026-33468 · WordPress · Drag/Drop Multiple File Upload

Leonid Semenenko

+1

·

Published

2026-04-17

·

Updated

2026-05-27

·

CVE-2026-5718

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drag and Drop Multiple File Upload for Contact Form 7 versions prior to 1.3.9.7
Description Insufficient file type validation occurs when custom blacklist types are configured, as the system replaces the default dangerous extension denylist instead of merging with it. Additionally, the wpcf7 antiscript file name() function can be bypassed using filenames containing non-ASCII characters. This allows unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, potentially leading to remote code execution.
Recommendations Update to a version later than 1.3.9.6.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-5718

Affected Products

Drag/Drop Multiple File Upload