Extension WordPress

Vulnérabilités Drag and Drop Multiple File Upload for Contact Form 7

Cette page rassemble les failles publiées pour Drag and Drop Multiple File Upload for Contact Form 7, leurs plages de versions affectées et les correctifs signalés dans la base locale.

18Vulnérabilités
1Critiques
18Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Drag and Drop Multiple File Upload for Contact Form 7

18 fiches

CVE-2026-8991 Moyenne · 4,4
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization…

Versions affectées

*-1.3.9.7

Correctif

1.3.9.8

Publication

05/06/2026

CVE-2026-49055 Élevée · 7,2
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Unauthenticated Stored Cross-Site Scripting

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.3.9.7

Correctif

1.3.9.8

Publication

03/06/2026

CVE-2026-5718 Élevée · 8,1
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when…

Versions affectées

*-1.3.9.7

Correctif

1.3.9.8

Publication

17/04/2026

CVE-2026-5710 Élevée · 7,5
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 – Unauthenticated Limited Arbitrary File Read via mfile Field

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using…

Versions affectées

*-1.3.9.6

Correctif

1.3.9.7

Publication

17/04/2026

CVE-2026-3459 Élevée · 8,1
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 – Unauthenticated Arbitrary File Upload

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This…

Versions affectées

*-1.3.9.5

Correctif

1.3.9.6

Publication

05/03/2026

CVE-2025-14457 Faible · 3,7
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 – Missing Authorization to Unauthenticated File Deletion

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including,…

Versions affectées

*-1.3.9.2

Correctif

1.3.9.3

Publication

14/01/2026

CVE-2025-14842 Moyenne · 6,1
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 – Unauthenticated Limited Arbitrary File Upload

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the…

Versions affectées

*-1.3.9.2

Correctif

1.3.9.3

Publication

06/01/2026

CVE-2025-8464 Moyenne · 5,3
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 – Directory Traversal via `wpcf7_guest_user_id` Cookie

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.3.9.0

Correctif

1.3.9.1

Publication

15/08/2025

CVE-2025-3515 Élevée · 8,1
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 – Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible…

Versions affectées

*-1.3.8.9

Correctif

1.3.9.0

Publication

16/06/2025

CVE-2025-2485 Élevée · 7,5
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 – Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This…

Versions affectées

*-1.3.8.8

Correctif

1.3.8.9

Publication

27/03/2025

CVE-2025-2328 Élevée · 8,8
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 – Unauthenticated Arbitrary File Deletion

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7.…

Versions affectées

*-1.3.8.7

Correctif

1.3.8.8

Publication

27/03/2025

CVE-2024-12267 Moyenne · 5,3
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 – Limited Arbitrary File Deletion

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including,…

Versions affectées

*-1.3.8.5

Correctif

1.3.8.6

Publication

30/01/2025

CVE-2024-3717 Moyenne · 5,3
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 – Sensitive Information Exposure

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated…

Versions affectées

*-1.3.7.7

Correctif

1.3.7.8

Publication

29/04/2024

CVE-2023-5822 Élevée · 8,1
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.3 – Unauthenticated Arbitrary File Upload

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This…

Versions affectées

*-1.3.7.3

Correctif

1.3.7.4

Publication

01/11/2023

CVE-2022-45364 Élevée · 8,8
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.5 – Cross-Site Request Forgery in dnd_upload_cf7_upload and dnd_codedropz_upload_delete

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.6.5. This is due to missing or incorrect nonce validation on the…

Versions affectées

*-1.3.6.5

Correctif

1.3.6.6

Publication

24/02/2023

CVE-2022-0595 Élevée · 7,2
Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.2 – Unauthenticated Stored Cross-Site Scripting

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

Versions affectées

*-1.3.6.2

Correctif

1.3.6.3

Publication

07/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités