Arbitrary File Upload Vulnerability in Drag and Drop Multiple File Upload for Contact Form 7 Plugin
CVE-2026-5718
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 April 2026
What is CVE-2026-5718?
The Drag and Drop Multiple File Upload plugin for Contact Form 7 is susceptible to an arbitrary file upload vulnerability due to inadequate validation of file types. Specifically, when custom blacklist types are set, the existing denylist is replaced instead of being combined, allowing dangerous file extensions to be uploaded. Additionally, the sanitization function wpcf7_antiscript_file_name() can be bypassed when dealing with filenames that contain non-ASCII characters. This flaw provides a pathway for unauthenticated attackers to upload malicious files, including PHP scripts, potentially leading to remote code execution on the server.
Affected Version(s)
Drag and Drop Multiple File Upload for Contact Form 7 0 <= 1.3.9.6