Junglewise Threat Intelligence

CVE-2026-18946: Contact Form to Any API predictable filename in file upload

CVE-2026-18946 · Severity: high · CVSS 7.5 · Published 2026-08-10

Vendors: Wordpress.

Executive brief

The Contact Form to Any API WordPress plugin stores user-uploaded files in a publicly accessible directory with predictable, non-random filenames. An unauthenticated attacker who knows the form ID and approximate submission time can enumerate and download files uploaded by other users, potentially exposing sensitive documents like resumes or personal information submitted through contact forms.

Technical details

The plugin copies files uploaded through Contact Form 7 forms to a publicly accessible directory (wp-content/uploads/cf7-to-any-api-uploads/) using predictable filenames based on form ID and Unix timestamp. The filename format cf7-{FORM_ID}-{UNIX_TIMESTAMP}.{extension} allows unauthenticated attackers to brute-force the timestamp within a narrow window (±60 seconds) around the submission time. Since the form ID is public and timestamps are sequential, an attacker requires only knowledge of the approximate submission time to systematically enumerate and retrieve uploaded files via HTTP requests without authentication. The vulnerability requires the site to have email delivery working (normal production state) and the plugin's entry hiding option disabled (default state). Fixed in version 3.0.7 with randomized filename generation.

Affected products

  • WordPress Contact Form to Any API before 3.0.7

Timeline

  • 2026-08-06: disclosed
  • 2026-08-10: patched: Version 3.0.7 released

References