CVE-2026-18781: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/plug-in/drag-and-drop-multiple-file-upload-for-contact-form-7to a version that resolves this vulnerability.Fixed in 1.3.9.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can exploit it; no authenticated WordPress account is required.
What condition enables code execution?
The attacker must be able to upload a file through the plugin. They can use control characters in the filename to bypass file-type restrictions after the filename is altered.
Which plugin versions are affected?
Versions earlier than 1.3.9.9 are affected. Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to 1.3.9.9 or later.