
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3459 is an arbitrary file upload vulnerability in the "Drag and Drop Multiple File Upload - Contact Form 7" WordPress plugin, caused by insufficient file type validation in the dnd_upload_cf7_upload function. It affects plugin versions up to and including 1.3.7.3 (ENISA lists affected versions as ≤1.3.9.5). Unauthenticated attackers can exploit this to upload arbitrary files to the server, potentially enabling remote code execution, but only when a form includes a multiple file upload field configured with * as the accepted file type. The vulnerability was published on March 5, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).
The root cause is CWE-434 (Unrestricted Upload of File with Dangerous Type): the dnd_upload_cf7_upload function fails to adequately validate uploaded file extensions or MIME types when the Contact Form 7 field is configured to accept all file types (*). An unauthenticated attacker can craft a multipart HTTP POST request to the vulnerable upload endpoint, supplying a malicious file (e.g., a PHP web shell) that bypasses the absent type checks. The exploit requires the specific precondition that a site administrator has configured a CF7 form with a drag-and-drop file upload field using * as the allowed file type — a non-default but not uncommon configuration. Source code references for the patched logic are available in the plugin's Trac repository (Plugin Trac, Plugin Changeset).
Successful exploitation allows an unauthenticated attacker to upload arbitrary files — including PHP web shells — to the web server, which can lead to full remote code execution under the web server's process privileges. This results in high confidentiality, integrity, and availability impact: attackers can read sensitive data (database credentials, user data), modify or delete site content, and potentially pivot to other systems on the same hosting environment. The scope is limited to the affected WordPress installation, but shared hosting environments amplify the risk of lateral movement to co-hosted sites (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.0016 (0.16%), indicating a low current probability of exploitation in the wild. The vulnerability is detected by Qualys (detection ID 531099) and has been catalogued by ENISA but does not appear in the CISA KEV catalog. Exploitation is constrained by the requirement that the target site's CF7 form must be configured with * as the accepted file type, raising the effective attack complexity (Wordfence Weekly Report, Qualys).
readme.txt files.* (all file types).shell.php containing <?php system($_GET['cmd']); ?>) and craft a multipart/form-data HTTP POST request targeting the plugin's upload endpoint (typically via the CF7 form submission or the AJAX handler dnd_upload_cf7_upload).wp-content/uploads/) and send an HTTP GET request to it with a command parameter (e.g., ?cmd=id) to execute arbitrary OS commands as the web server user (Plugin Trac, Wordfence).wp-admin/admin-ajax.php with action=dnd_upload_cf7_upload) containing PHP or executable file content; outbound connections from the web server process to unknown external IPs..php, .phtml, .phar, or other executable files appearing in wp-content/uploads/ directories; newly created files with web shell signatures (e.g., system(), exec(), passthru(), base64_decode() in uploaded files).wp-content/uploads/ with query parameters resembling command execution (e.g., ?cmd=, ?c=, ?exec=); HTTP 200 responses to requests for .php files in the uploads directory.bash, sh, curl, wget, or python with suspicious arguments.Update the "Drag and Drop Multiple File Upload - Contact Form 7" plugin to version 1.3.9.5 or later, which contains the patched dnd_upload_cf7_upload function with proper file type validation (Plugin Changeset). As an immediate workaround, administrators should audit all CF7 forms and change any file upload field configured with * as the accepted file type to an explicit allowlist of safe, non-executable extensions (e.g., pdf|jpg|png). Additionally, configure the web server to deny direct execution of PHP files within the wp-content/uploads/ directory as a defense-in-depth measure.
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 2–8, 2026, providing the primary technical advisory (Wordfence Weekly Report). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Community discussion was noted on Mastodon via RedPacketSecurity, and the vulnerability was indexed by multiple threat intelligence aggregators including VulDB, Vulners, and INCIBE shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."