CVE-2026-3459: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3459 is an arbitrary file upload vulnerability in the "Drag and Drop Multiple File Upload - Contact Form 7" WordPress plugin, caused by insufficient file type validation in the dnd_upload_cf7_upload function. It affects plugin versions up to and including 1.3.7.3 (ENISA lists affected versions as ≤1.3.9.5). Unauthenticated attackers can exploit this to upload arbitrary files to the server, potentially enabling remote code execution, but only when a form includes a multiple file upload field configured with * as the accepted file type. The vulnerability was published on March 5, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-434 (Unrestricted Upload of File with Dangerous Type): the dnd_upload_cf7_upload function fails to adequately validate uploaded file extensions or MIME types when the Contact Form 7 field is configured to accept all file types (*). An unauthenticated attacker can craft a multipart HTTP POST request to the vulnerable upload endpoint, supplying a malicious file (e.g., a PHP web shell) that bypasses the absent type checks. The exploit requires the specific precondition that a site administrator has configured a CF7 form with a drag-and-drop file upload field using * as the allowed file type — a non-default but not uncommon configuration. Source code references for the patched logic are available in the plugin's Trac repository (Plugin Trac, Plugin Changeset).

Impact

Successful exploitation allows an unauthenticated attacker to upload arbitrary files — including PHP web shells — to the web server, which can lead to full remote code execution under the web server's process privileges. This results in high confidentiality, integrity, and availability impact: attackers can read sensitive data (database credentials, user data), modify or delete site content, and potentially pivot to other systems on the same hosting environment. The scope is limited to the affected WordPress installation, but shared hosting environments amplify the risk of lateral movement to co-hosted sites (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.0016 (0.16%), indicating a low current probability of exploitation in the wild. The vulnerability is detected by Qualys (detection ID 531099) and has been catalogued by ENISA but does not appear in the CISA KEV catalog. Exploitation is constrained by the requirement that the target site's CF7 form must be configured with * as the accepted file type, raising the effective attack complexity (Wordfence Weekly Report, Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Drag and Drop Multiple File Upload - Contact Form 7" plugin version ≤1.3.7.3 using tools like WPScan, Shodan, or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Identify vulnerable form: Browse the target site to locate a Contact Form 7 form that includes a drag-and-drop file upload field. Inspect the form's HTML or CF7 shortcode to confirm the field accepts * (all file types).
  3. Craft malicious upload request: Prepare a PHP web shell file (e.g., shell.php containing <?php system($_GET['cmd']); ?>) and craft a multipart/form-data HTTP POST request targeting the plugin's upload endpoint (typically via the CF7 form submission or the AJAX handler dnd_upload_cf7_upload).
  4. Upload the payload: Submit the crafted request, bypassing the insufficient file type validation. The server accepts and stores the PHP file in the WordPress uploads directory.
  5. Achieve remote code execution: Determine the uploaded file's URL (typically under wp-content/uploads/) and send an HTTP GET request to it with a command parameter (e.g., ?cmd=id) to execute arbitrary OS commands as the web server user (Plugin Trac, Wordfence).

Indicators of compromise

  • Network: Unusual multipart POST requests to WordPress AJAX endpoints (e.g., wp-admin/admin-ajax.php with action=dnd_upload_cf7_upload) containing PHP or executable file content; outbound connections from the web server process to unknown external IPs.
  • File System: Unexpected .php, .phtml, .phar, or other executable files appearing in wp-content/uploads/ directories; newly created files with web shell signatures (e.g., system(), exec(), passthru(), base64_decode() in uploaded files).
  • Logs: Web server access logs showing POST requests to the CF7 upload handler followed shortly by GET requests to files in wp-content/uploads/ with query parameters resembling command execution (e.g., ?cmd=, ?c=, ?exec=); HTTP 200 responses to requests for .php files in the uploads directory.
  • Process: Unusual child processes spawned by the web server (e.g., Apache/Nginx/PHP-FPM) such as bash, sh, curl, wget, or python with suspicious arguments.

Mitigation and workarounds

Update the "Drag and Drop Multiple File Upload - Contact Form 7" plugin to version 1.3.9.5 or later, which contains the patched dnd_upload_cf7_upload function with proper file type validation (Plugin Changeset). As an immediate workaround, administrators should audit all CF7 forms and change any file upload field configured with * as the accepted file type to an explicit allowlist of safe, non-executable extensions (e.g., pdf|jpg|png). Additionally, configure the web server to deny direct execution of PHP files within the wp-content/uploads/ directory as a defense-in-depth measure.

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 2–8, 2026, providing the primary technical advisory (Wordfence Weekly Report). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Community discussion was noted on Mastodon via RedPacketSecurity, and the vulnerability was indexed by multiple threat intelligence aggregators including VulDB, Vulners, and INCIBE shortly after disclosure.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management