CVE-2026-5364Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fact that validation occurs on the unsanitized extension while the file is saved with a sanitized extension, allows special characters like '$' to be stripped during the save process. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and potentially achieve remote code execution, however, an .htaccess file and name randomization is in place which restricts real-world exploitability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-25: 1Mentions · 2026-05-18: 1Technical Details · 2026-04-25: 104-2505-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-251
Disclosure1
2026-05-181
General1
Full discourse2 posts
  • ✗'Kawa@kawayeni
    General

    CVE-2026-5364 </3

    Post summary

    The text only references CVE-2026-5364 with no additional details or actionable information.

    00090742
    420 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5364 The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the… https://www.cve.org/CVERecord?id=CVE-2026-5364

    Post summary

    The text announces a CVE for an arbitrary file upload flaw in the Drag and Drop File Upload plugin for Contact Form 7, affecting versions up to 1.1.3, with a link to the official CVE record for further details.

    00000108
    57.2K followersView on X

Explore more