
CVE-2026-5364 </3
Post summary
The text only references CVE-2026-5364 with no additional details or actionable information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fact that validation occurs on the unsanitized extension while the file is saved with a sanitized extension, allows special characters like '$' to be stripped during the save process. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and potentially achieve remote code execution, however, an .htaccess file and name randomization is in place which restricts real-world exploitability.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-04-25 | 1 | Disclosure1 |
| 2026-05-18 | 1 | General1 |

CVE-2026-5364 </3
Post summary
The text only references CVE-2026-5364 with no additional details or actionable information.

CVE-2026-5364 The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the… https://www.cve.org/CVERecord?id=CVE-2026-5364
Post summary
The text announces a CVE for an arbitrary file upload flaw in the Drag and Drop File Upload plugin for Contact Form 7, affecting versions up to 1.1.3, with a link to the official CVE record for further details.