CVE-2026-18781Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 308-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-18781 Arbitrary Code Execution in Contact Form 7 Plugin via File Name V... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18781 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    An announcement of CVE-2026-18781, stating an arbitrary code execution vulnerability in Contact Form 7 via file name, with a link to details but no PoC, exploit, or patch information.

    01010108
    4.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-18781 (CVSS 8.1): Drag and Drop Multiple File Upload for Contact Form 7 plugin <1.3.9.9 fails to validate uploaded file names. Update immediately if in use. https://nvd.nist.gov/vuln/… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/iuGqMw15ZA

    Post summary

    The tweet highlights a high-severity CVE in Contact Form 7, urges an immediate patch, and provides brief technical details of the vulnerability.

    0000035
    93 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18781 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping charact… https://www.cve.org/CVERecord?id=CVE-2026-18781

    Post summary

    The text announces CVE-2026-18781, noting that Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin versions before 1.3.9.9 fails to validate the final file name after stripping characters, which could lead to improper file uploads.

    000001.0K
    58.0K followersView on X

Explore more