CVE-2026-18946: Unknown Contact Form To Any API
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
Affected products
- Unknown Contact Form To Any API: before 3.0.7 (fixed in 3.0.7)
Published 2026-08-10. Last modified 2026-08-26.