The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
We have discovered 18,162 live websites that are affected by CVE-2026-18781.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 18,162 live websites (100% of Drag And Drop Multiple File Upload Contact Form 7 install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 60 versions ( 100% of all versions) |
| 3,301 websites | |
| 3,676 websites | |
| 962 websites | |
| 891 websites | |
| 833 websites | |
| 756 websites | |
| 701 websites | |
| 664 websites | |
| 573 websites | |
| 454 websites |
| .com | 5,392 websites |
| .de | 2,817 websites |
| .ru | 616 websites |
| .co.uk | 568 websites |
| .nl | 541 websites |
| .org | 533 websites |
| .it | 508 websites |
| .pl | 501 websites |
| .fr | 478 websites |
| .com.au | 372 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********************.com | **,*** | ||
| ******.cc | **,*** | ||
| ********.me | **,*** | ||
| ****.hr | **,*** | ||
| ******.pt | **,*** | ||
| ****************.org | **,*** | ||
| *******.com | **,*** | ||
| ****.si | **,*** | ||
| *******.org | **,*** | ||
| **********************.**.uk | **,*** |
FAQ