HIGH
glenwpcoder
CVE published 2026-04-17
CVE-2026-5718
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin contains an arbitrary file upload vulnerability affecting versions up to and including 1.3.9.7. The flaw stems from two weaknesses: insufficient file type validation when custom blacklist types are configured (which replaces rather than merges with the default dangerous extension denylist), and a bypass of the wpcf7_antiscript_file [truncated]