CVE-2026-5710Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is directly appended to the plugin's upload URL without sanitization. In dnd_cf7_mail_components(), the URL is converted back to a filesystem path using str_replace() and only file_exists() is used as the acceptance check before attaching the file to the outgoing CF7 email. This makes it possible for unauthenticated attackers to read and exfiltrate arbitrary files readable by the web server process via path traversal sequences in the mfile[] parameter, with files being disclosed as email attachments. Note: This vulnerability is limited to the 'wp-content' folder due to the wpcf7_is_file_path_in_content_dir() function in the Contact Form 7 plugin.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 104-1704-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure2
2026-04-191
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5710 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and incl… https://www.cve.org/CVERecord?id=CVE-2026-5710

    Post summary

    The post announces that CVE-2026-5710 is a path‑traversal flaw in a WordPress plugin permitting arbitrary file reads, citing a CVE record link but providing no PoC, exploit, or patch information.

    00000108
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5710 Path Traversal Leading to Arbitrary File Read in Drag and Drop Multiple File Upload for Contact Form 7 Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5710

    Post summary

    The text announces CVE-2026-5710, a path traversal flaw in Contact Form 7 that allows arbitrary file reads, without mentioning PoC, exploit code, patch, or active exploitation.

    0000069
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5710 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading … CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5710 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post announces a high‑severity Path Traversal vulnerability (CVE‑2026‑5710) in the Drag and Drop Multiple File Upload plugin for Contact Form 7, providing its CVSS score and a link to a detailed analysis.

    000003
    145 followersView on X

Explore more