CVE-2026-18946: Unknown Contact Form To Any API

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.

Affected products

  • Unknown Contact Form To Any API: before 3.0.7 (fixed in 3.0.7)

Published 2026-08-10. Last modified 2026-08-26.