S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 15, 2026

CVE-2026-5718 Scanner

CVE-2026-5718 Scanner - Remote Code Execution vulnerability in Drag and Drop Multiple File Upload for Contact Form 7

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-5718
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution. The vulnerability was originally reported by Leonid Semenenko (lsemenenko) and partially patched in version 1.3.9.7. A bypass for the patch was separately discovered and reported by Nguyen Hung (Mitchell).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Drag and Drop Multiple File Upload for Contact Form 7by glenwpcoder
0
Updated Aug 22, 2026View on NVD →
Detail

This scanner focuses on the Drag and Drop Multiple File Upload plugin for Contact Form 7, a widely-used WordPress plugin developed to enhance contact form functionalities by allowing multiple file uploads through drag-and-drop actions. The software is commonly used by website administrators and developers who leverage WordPress for building and managing websites. This plugin integrates with the Contact Form 7 platform, facilitating seamless file interactions as part of form submission processes. It is designed to cater to users requiring robust and flexible contact form solutions, offering enhanced user experience through its drag-and-drop file feature. As part of the WordPress ecosystem, it is extensively utilized across various industries, serving small to large enterprises aiming for efficient form handling.

The vulnerability addressed by this scanner is a Remote Code Execution (RCE) issue arising from the Drag and Drop Multiple File Upload plugin for Contact Form 7. The flaw involves insufficient file validation checks, allowing unauthenticated attackers to upload arbitrary files, including malicious ones, to the server. The vulnerability is exacerbated by inadequate filename sanitization mechanisms, particularly with non-ASCII characters. As a result, this allows attackers to bypass security measures and execute unauthorized code remotely. This vulnerability represents a critical security risk, potentially leading to severe implications for affected systems if not addressed promptly.

Technical details of the vulnerability reveal that it stems from the plugin's handling of file uploads, specifically the content-type application/octet-stream used during file submission. Affected endpoints include those responsible for handling multipart form data containing malicious file payloads. By exploiting weak nonce protection strategies and taking advantage of an attacker-controlled 'upload-file' field, unauthorized code execution becomes feasible. The template employs numerous HTTP requests and response verification steps to ascertain successful exploitation, with matchers confirming payload delivery and file execution paths.

Successful exploitation of this vulnerability allows threat actors to take full control of the web server hosting the vulnerable plugin. Potential effects include unauthorized access to sensitive information or databases, defacement or modification of website content, and use of the compromised server to launch further attacks. Attackers may implant persistent backdoors, leading to long-term access and seriously compromising the confidentiality, integrity, and availability of hosted content and data.

REFERENCES

Solution Advice
  • Update the Drag and Drop Multiple File Upload plugin to a version beyond 1.3.9.6 to address the vulnerability and related security risks.
  • Conduct a thorough review and enhancement of file upload validation processes in web applications.
  • Implement additional security controls that restrict unauthorized file types at the server and application layers.
  • Enable server-level defenses such as web application firewalls to detect and block malicious payloads.
  • Regularly audit WordPress plugins and themes for known vulnerabilities and keep them updated.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.