CVE-2026-18781

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.


We have discovered 18,162 live websites that are affected by CVE-2026-18781.

Run a Free Instant Scan




Affected Software

Product  Drag And Drop Multiple File Upload Contact Form 7
Category Wordpress Plugins
Vulnerable Domains18,162 live websites (100% of Drag And Drop Multiple File Upload Contact Form 7 install base)
Vulnerable Versions
  • from 0 through 1.3.9.9
Vulnerable Versions Count60 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Aug 21, 2026
  • Updated - Aug 21, 2026

Credits

  • Jakub Herman (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18781
United States3,301 websites



Germany3,676 websites
France962 websites
Japan891 websites
GB833 websites
Russia756 websites
Poland701 websites
Italy664 websites
Netherlands573 websites
Spain454 websites

Website Distribution by TLD

Number of websites using CVE-2026-18781
.com5,392 websites
.de2,817 websites
.ru616 websites
.co.uk568 websites
.nl541 websites
.org533 websites
.it508 websites
.pl501 websites
.fr478 websites
.com.au372 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18781

Top websites that are affected by CVE-2026-18781. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********************.com United States**,***
******.cc Malaysia**,***
********.me United States**,***
****.hr Croatia**,***
******.pt Portugal**,***
****************.org United States**,***
*******.com Italy**,***
****.si Slovenia**,***
*******.org France**,***
**********************.**.uk GB**,***
See full domain list

FAQ

CVE-2026-18781 is Improper Control of Generation of Code ('Code Injection') in Drag And Drop Multiple File Upload Contact Form 7
A total of 18,162 websites have been identified as vulnerable to CVE-2026-18781, based on global website indexing conducted by WebTechSurvey.
The Drag And Drop Multiple File Upload Contact Form 7 is affected by the CVE-2026-18781 vulnerability.
Drag And Drop Multiple File Upload Contact Form 7 versions up to 1.3.9.9 are vulnerable to CVE-2026-18781.
CVE-2026-18781 is resolved in version 1.3.9.9 of Drag And Drop Multiple File Upload Contact Form 7.