CVE-2026-5364 is an arbitrary file upload vulnerability in the Drag and Drop File Upload for Contact Form 7 WordPress plugin affecting versions up to and including 1.1.3. The flaw stems from inconsistent handling of uploaded file extensions and attacker control over the file type parameter. Specifically, the plugin extracts and validates the file extension before sanitization, while the uploaded file is ultimately saved using a sanitized extension. Because validation is performed on the unsanitized extension and the saved filename uses the sanitized extension, special characters such as '$' can be removed during the save process, enabling an attacker to bypass extension checks and upload a PHP file. The issue is further enabled by the plugin allowing the attacker to control the file type parameter instead of strictly enforcing administrator-configured allowed types. As a result, an unauthenticated attacker may be able to upload arbitrary PHP files and potentially reach remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script, CVE-2026-5364.py, plus a README. The script is a real unauthenticated exploit for CVE-2026-5364 affecting the WordPress plugin Drag and Drop File Upload for Contact Form 7 <= 1.1.3. Its purpose is to automate discovery of a usable nonce, abuse the vulnerable AJAX upload flow, upload a PHP webshell using a sanitize_file_name() bypass (for example shell.php$ becoming shell.php after sanitization), parse the returned upload URL, and then trigger remote command execution through the uploaded shell. Repository structure is simple: one operational Python CLI tool and one documentation file. The Python script appears to support both single-target and bulk-target modes, multithreading via ThreadPoolExecutor, session/proxy handling with requests, result saving, verbose output, and an optional interactive shell mode. The README confirms multiple shell payload types (system, shell_exec, passthru, eval, phpinfo), command customization, thread count, timeout, proxy support, and output file handling. Main exploit capability: unauthenticated arbitrary file upload leading to RCE. The exploit chain described is: retrieve a public nonce from a page containing the form, POST a crafted upload request to /wp-admin/admin-ajax.php with action=cf7_file_uploads and attacker-controlled type/file values, receive a JSON response containing the uploaded file URL, then invoke the uploaded PHP shell with a cmd parameter or POST body depending on shell type. The script also handles the case where upload succeeds but code execution is blocked, indicating partial success. Fingerprintable targets/endpoints include the WordPress AJAX endpoint /wp-admin/admin-ajax.php, the upload directory /wp-content/uploads/cf7-uploads-custom/, and example form pages such as /contact/. The exploit is network/web-based and operational rather than a mere PoC because it includes working payloads, automation, scanning, and interactive post-upload command execution.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.