CVE-2026-18946 UNKNOWN

CVE-2026-18946

Published: 2026-08-10

Description

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…