CVE-2026-5718 affects the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin in versions up to and including 1.3.9.7. The plugin is vulnerable to arbitrary file upload because file type validation is insufficient when custom blacklist types are configured: the custom blacklist replaces the plugin’s default dangerous-extension denylist instead of being merged with it. In addition, the wpcf7_antiscript_file_name() sanitization logic can be bypassed using filenames containing non-ASCII characters. Together, these flaws allow an unauthenticated attacker to upload arbitrary files, including server-executable PHP payloads, to the target WordPress server. If the uploaded file is placed in a web-accessible location and interpreted by the server, this can be leveraged for remote code execution. The issue was reportedly only partially patched in 1.3.9.7, and a bypass for that patch was later identified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a self-contained local Docker lab and proof-of-concept for CVE-2026-5718, an unauthenticated arbitrary file upload vulnerability in the WordPress plugin Drag and Drop Multiple File Upload for Contact Form 7. The repo contains 8 files total, with the main exploit logic in poc/poc.py, environment orchestration in docker-compose.yml, WordPress image setup in vuln/Dockerfile and patched/Dockerfile, and lab seeding logic in scripts/seed-wordpress.sh. The exploit capability is web-based unauthenticated file upload leading to code execution in the intentionally vulnerable lab. The Python PoC first enforces a safety restriction by only allowing localhost or loopback base URLs. It fetches the seeded lab page /cve-2026-5718-lab/, extracts the plugin AJAX nonce from HTML, then submits a multipart POST to /wp-admin/admin-ajax.php using action=dnd_codedropz_upload. The uploaded file is a PHP proof named proof-β.php, where the non-ASCII beta character is central to the blacklist bypass condition described in the README. If the upload succeeds, the script reconstructs the expected file URL under /wp-content/uploads/wp_dndcf7_uploads/wpcf7-files/cve5718proof/ and requests it to determine whether the PHP executed, was served as text, was blocked with 403, or was unreachable. The payload is intentionally minimal and non-persistent: a PHP script that prints a marker string plus the output of whoami and id. This demonstrates execution as the web server user but does not include a reverse shell, persistence, credential theft, or lateral movement. Because the payload is embedded and fixed, the exploit is best classified as OPERATIONAL rather than weaponized. The repository structure supports side-by-side comparison of vulnerable and patched behavior. docker-compose.yml launches two WordPress stacks: vuln on localhost:8081 with plugin version 1.3.9.6 and patched on localhost:8082 with version 1.3.9.7, each backed by separate MySQL 8.0 containers. The seed-wordpress.sh script installs WordPress, Contact Form 7, the target plugin version, creates the proof form and page, prepares upload directories, and writes an .htaccess file. For the vulnerable profile it intentionally allows PHP execution in the upload directory so the impact is observable; for the patched profile it denies access to .php and .phar files. This means the repo is not just a detector: it performs the upload and validates post-upload execution behavior in a controlled lab. Overall, the repository’s purpose is educational and comparative: to reproduce the vulnerable upload path in plugin version 1.3.9.6, show that a non-ASCII filename can preserve a .php upload, and contrast that with patched version 1.3.9.7 where the same upload is rejected.
Repository contains a single Python exploit script and a README. The Python file is an operational unauthenticated RCE exploit for CVE-2026-5718 affecting the WordPress plugin Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6. The exploit automates the full attack chain: it requests a nonce from the public WordPress AJAX endpoint /wp-admin/admin-ajax.php using the _wpcf7_check_nonce action, abuses the plugin's blacklist replacement logic so dangerous extensions such as .php are no longer blocked when a custom blacklist is configured, uses a non-ASCII filename to bypass antiscript filename rewriting, uploads a PHP webshell, and then attempts to verify command execution. The script supports multiple PHP shell payloads (system, passthru, exec, assert, base64-eval, and a fuller fallback shell), single-target and bulk-target modes, threading, proxy support, timeout control, output logging, and post-exploitation verification via a configurable command. The attack is web-based and network-reachable, targeting exposed WordPress AJAX handlers and uploaded shell paths. README content aligns with the code and documents the vulnerability chain, affected versions, exploitation prerequisites, and mitigation guidance.
This repository is a self-contained local Docker lab and PoC for CVE-2026-5718, an unauthenticated arbitrary file upload vulnerability in the WordPress plugin Drag and Drop Multiple File Upload for Contact Form 7. The repo contains 8 files total, with the main exploit logic in `poc/poc.py`, environment orchestration in `docker-compose.yml`, setup automation in `scripts/seed-wordpress.sh`, and two nearly identical Dockerfiles for vulnerable and patched WordPress containers. The exploit capability is straightforward: the Python PoC fetches the seeded lab page, extracts the plugin AJAX nonce from HTML, uploads a PHP file named `proof-β.php` via `wp-admin/admin-ajax.php` using action `dnd_codedropz_upload`, parses the JSON response to reconstruct the uploaded file URL under `/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files/`, then requests that file to verify whether PHP executed. Successful exploitation is confirmed by a marker string and the output of `whoami` and `id`. This is an actual exploit PoC rather than a detector, though it is intentionally constrained to localhost/loopback targets. Repository structure and purpose: - `poc/poc.py`: main exploit script; includes localhost-only guard, nonce extraction, upload request construction, uploaded URL derivation, and execution-result analysis. - `scripts/seed-wordpress.sh`: provisions WordPress, installs Contact Form 7 and the target plugin version, creates the vulnerable form/page, prepares upload directories, and toggles `.htaccess` behavior so the vulnerable lab visibly executes uploaded PHP while the patched lab blocks it. - `docker-compose.yml`: launches four services (`vuln`, `patched`, and two MySQL backends) on ports 8081 and 8082. - `vuln/Dockerfile` and `patched/Dockerfile`: build WordPress containers and install WP-CLI for automated seeding. - `README.md`: documents the vulnerability, lab architecture, expected results, and safety constraints. The exploit targets plugin version 1.3.9.6 and contrasts behavior with patched version 1.3.9.7. The attack vector is web-based unauthenticated file upload leading to code execution when the upload directory permits PHP execution. The payload is minimal and hardcoded, making the exploit operational but not weaponized.
Repository contains a standalone Python exploit toolkit plus a copy of the vulnerable WordPress plugin source file and supporting documentation. The main offensive components are exploit_cve_2026_5718.py and discover_forms.py. exploit_cve_2026_5718.py is a mass-target exploitation script for alleged CVE-2026-5718 affecting the WordPress plugin 'Drag & Drop Multiple File Upload for Contact Form 7'. It reads targets from a file, optionally extracts a nonce from the target homepage, then sends unauthenticated multipart POST requests to /wp-admin/admin-ajax.php using action=dnd_codedropz_upload. It implements two upload vectors: (1) direct upload of shell.php relying on blacklist misconfiguration/replacement, and (2) upload of shell.php with a zero-width joiner before .pdf to bypass filename sanitization. Successful responses are parsed as JSON and the returned filename is logged. The payloads are active PHP webshells enabling command execution or arbitrary PHP execution, so this is a real exploit rather than a detector. The reconnaissance component, discover_forms.py, is a helper script for identifying Contact Form 7 form IDs needed by the exploit. It checks whether a site appears to be WordPress, then enumerates forms by parsing homepage/internal HTML, querying the REST API endpoint /wp-json/contact-form-7/v1/forms, crawling /sitemap.xml, and checking common contact-related paths. It outputs discovered form IDs in a pipe-delimited format suitable for later batch exploitation. This script is primarily a discovery/enumeration utility, not the exploit itself. The repository also includes cve_2026_5718_test.php, which is a local verification/demo script that models the vulnerable logic in PHP and demonstrates the two bypass concepts without attacking a remote target. drag.php appears to be a large excerpt/copy of the plugin source. Relevant code shown registers unauthenticated AJAX handlers wp_ajax_nopriv_dnd_codedropz_upload and wp_ajax_nopriv__wpcf7_check_nonce, confirming the attack surface the exploit targets. Documentation files (QUICK_START.md, README_DISCOVER_FORMS.md, README_MASS_EXPLOIT.md) explain workflow, target preparation, form discovery, and exploitation steps. Several markdown/text files are empty placeholders. Overall, the repository’s purpose is to support unauthenticated web exploitation of a WordPress file upload flaw at scale, from reconnaissance through payload upload and result logging.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Specific vulnerability identified as CVE-2026-5718, referenced in a pull request creating and updating a YAML definition, but no technical details about the flaw are provided in the content.
A critical remote code execution vulnerability in Drag and Drop Multiple File Upload CF7.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.