CVE-2020-35489 refers to an unrestricted file upload vulnerability discovered in Contact Form 7 versions prior to 5.3.2. This vulnerability arose due to insufficient validation of filenames submitted through contact forms. An attacker could exploit this flaw to upload malicious files of any type, bypassing security restrictions that might be in place to limit allowed file uploads (e.g., only allowing images or PDFs).