CVE-2026-18946: Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18946?
CVE-2026-18946 has a risk score of 62, indicating a moderate severity vulnerability.
How do I fix CVE-2026-18946?
To fix CVE-2026-18946, update the Contact Form to Any API plugin to version 3.0.7 or later.
What type of vulnerability is represented by CVE-2026-18946?
CVE-2026-18946 is an unauthenticated sensitive file disclosure vulnerability due to predictable filenames.
Who is affected by CVE-2026-18946?
Users of the Contact Form to Any API WordPress plugin versions prior to 3.0.7 are affected by CVE-2026-18946.
What can attackers do with CVE-2026-18946?
Attackers can enumerate and download sensitive files submitted through contact forms due to this vulnerability.