CVE-2026-18781
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
| Vendor | unknown |
| Product | drag and drop multiple file upload for contact form 7 |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown drag and drop multiple file upload for contact form 7
Be the first to know when new unknown vulnerabilities affecting unknown drag and drop multiple file upload for contact form 7 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Drag and Drop Multiple File Upload for Contact Form 7
0 < 1.3.9.9
References
Credits
Jakub Herman WPScan