EIP-2026-113692
PRE-CVEWordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113692. PoCs published by Austin Martin.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote code execution vulnerability in the WordPress plugin 'Drag and Drop Multiple File Upload - Contact Form 7' version 1.3.3.2. It bypasses file type restrictions by appending '%' to the file type and filename, allowing the upload of a malicious PHP file.
Description
WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution
Exploits (1)
This exploit demonstrates an unauthenticated remote code execution vulnerability in the WordPress plugin 'Drag and Drop Multiple File Upload - Contact Form 7' version 1.3.3.2. It bypasses file type restrictions by appending '%' to the file type and filename, allowing the upload of a malicious PHP file.