Skip to main content
QUIETLYTIC
Vulnerability

Drag and Drop Multiple File Upload for Contact Form 7 Code Injection (CVE-2026-18781)

CVE-2026-18781 is a CVSS 8.1 code injection in a Contact Form 7 WordPress add-on, reported exploited by VulnCheck alone.

CVE-2026-18781
Threat Level
HIGH
CVSS
8.1
Status
Active Exploitation
Confidence
Medium
Affected Products
Drag and Drop Multiple File Upload for Contact Form 7 (before 1.3.9.9)

CVE-2026-18781 carries a CVSS 3.1 base score of 8.1 against Drag and Drop Multiple File Upload for Contact Form 7, a WordPress plugin. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and states the flaw is fixed in version 1.3.9.9, meaning all earlier versions are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated August 24, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-18781 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states the plugin does not validate the final name of an uploaded file after stripping characters from it, allowing an unauthenticated attacker to defeat its file type restrictions and execute arbitrary code on the server. The CVSS vector marks this fully unauthenticated (PR:N) with high attack complexity (AC:H), consistent with a filter-bypass flaw that requires a specifically crafted filename rather than a straightforward file upload.

We are reporting the class of validation gap NVD describes — filtering that runs before, rather than after, characters are stripped from the filename — without detailing the specific filename construction needed to defeat it.

Evidence and confidence

  • Medium confidence — the CVSS 8.1 score, the vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, the fixed version (1.3.9.9), and the described validation gap all trace to NVD alone in our current ingestion, corroborated by WPScan’s vulnerability entry for this CVE. The exploitation report traces to VulnCheck KEV alone.
  • Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.0032, a 25.1st percentile score as of our ingestion.

No field is in conflict between our two sources.

Why this matters

File-upload filters that validate a filename before applying character-stripping logic, rather than after, are a recurring WordPress plugin failure pattern: the check passes against the pre-stripped name, but the file that actually lands on disk is the post-stripped version, which can carry a different (and dangerous) extension. Contact form plugins are especially exposed because file upload is a core, publicly reachable feature by design, not an edge case — any WordPress site accepting public form submissions with file attachments via this plugin should treat this as directly reachable by anonymous visitors.

Frequently Asked Questions

What is CVE-2026-18781? A CVSS 8.1 code injection vulnerability (CWE-94) in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before version 1.3.9.9, allowing unauthenticated attackers to bypass file type restrictions and execute arbitrary code.

Is CVE-2026-18781 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 24, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description states the attack is achievable by unauthenticated users, though the CVSS vector’s high attack-complexity rating reflects the crafted-filename requirement.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Version 1.3.9.9, per NVD.


Severity, vector, weakness classification, and the described validation gap sourced from the National Vulnerability Database record for CVE-2026-18781, corroborated by WPScan’s vulnerability entry. Exploitation status and the August 24, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools