High severity8.1NVD Advisory· Published Aug 21, 2026· Updated Aug 26, 2026
CVE-2026-18781
CVE-2026-18781
Description
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)Wordfence Blog · Sep 3, 2026
- WordPress: 25 Plugin Vulnerabilities Disclosed Together, Including Critical FlawsVypr Intelligence · Aug 21, 2026