CVE-2026-18946
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH


