CVE-2026-5364: Unauthenticated File Upload Flaw in WordPress Contact Form 7 Plugin
A high-severity flaw in the Drag and Drop File Upload plugin for Contact Form 7 exposes WordPress sites to unauthenticated arbitrary PHP file uploads. CVSS 8.1 HIGH.
Team Nippysoft