PT-2026-33468 · WordPress · Drag/Drop Multiple File Upload
Leonid Semenenko
+1
·
Published
2026-04-17
·
Updated
2026-05-27
·
CVE-2026-5718
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Drag and Drop Multiple File Upload for Contact Form 7 versions prior to 1.3.9.7
Description
Insufficient file type validation occurs when custom blacklist types are configured, as the system replaces the default dangerous extension denylist instead of merging with it. Additionally, the
wpcf7 antiscript file name() function can be bypassed using filenames containing non-ASCII characters. This allows unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, potentially leading to remote code execution.Recommendations
Update to a version later than 1.3.9.6.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drag/Drop Multiple File Upload