Kaitan ID Security[verified]@KaitanSecurityDisclosure
A high‑severity CVE-2026-5718 vulnerability (arbitrary file upload, CVSS 8.1) has been disclosed for the Contact Form 7 plugin, with analysis linked.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE-2026-5718, detailing an arbitrary file upload flaw in Contact Form 7’s drag‑and‑drop upload feature, but it does not provide a PoC, exploit code, or remediation guidance.
CTIWatch@ctiwatchcloudActive Exploitation
An alert declares that CVE-2026-5718 is actively exploited in the wild against the Drag and Drop Multiple File Upload plugin for Contact Form 7, with a CVSS score of 8.1, though no PoC or patch information is provided.
CVE@CVEnewDisclosure
CVE-2026-5718 identifies an arbitrary file upload vulnerability in Drag and Drop Multiple File Upload for Contact Form 7 plugin (versions up to 1.3.9.6). No exploitation or patch information is provided.