Extension WordPress
Vulnérabilités Drag and Drop Multiple File Upload for Contact Form 7
Cette page rassemble les failles publiées pour Drag and Drop Multiple File Upload for Contact Form 7, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Drag and Drop Multiple File Upload for Contact Form 7
18 fiches
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization…
*-1.3.9.7
1.3.9.8
05/06/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Unauthenticated Stored Cross-Site Scripting
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.9.7
1.3.9.8
03/06/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 – Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when…
*-1.3.9.7
1.3.9.8
17/04/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 – Unauthenticated Limited Arbitrary File Read via mfile Field
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using…
*-1.3.9.6
1.3.9.7
17/04/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 – Unauthenticated Arbitrary File Upload
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This…
*-1.3.9.5
1.3.9.6
05/03/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 – Missing Authorization to Unauthenticated File Deletion
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including,…
*-1.3.9.2
1.3.9.3
14/01/2026
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 – Unauthenticated Limited Arbitrary File Upload
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the…
*-1.3.9.2
1.3.9.3
06/01/2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 – Directory Traversal via `wpcf7_guest_user_id` Cookie
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers…
*-1.3.9.0
1.3.9.1
15/08/2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 – Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible…
*-1.3.8.9
1.3.9.0
16/06/2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 – Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This…
*-1.3.8.8
1.3.8.9
27/03/2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 – Unauthenticated Arbitrary File Deletion
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7.…
*-1.3.8.7
1.3.8.8
27/03/2025
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 – Limited Arbitrary File Deletion
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including,…
*-1.3.8.5
1.3.8.6
30/01/2025
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 – Sensitive Information Exposure
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated…
*-1.3.7.7
1.3.7.8
29/04/2024
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.3 – Unauthenticated Arbitrary File Upload
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This…
*-1.3.7.3
1.3.7.4
01/11/2023
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.5 – Cross-Site Request Forgery in dnd_upload_cf7_upload and dnd_codedropz_upload_delete
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.6.5. This is due to missing or incorrect nonce validation on the…
*-1.3.6.5
1.3.6.6
24/02/2023
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.4 – File Upload Size Limit Bypass
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to File Upload Size Limit Bypass in versions up to, and including, 1.3.6.4. This is due to the plugin accepting the file…
*-1.3.6.4
1.3.6.5
26/09/2022
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.2 – Unauthenticated Stored Cross-Site Scripting
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
*-1.3.6.2
1.3.6.3
07/03/2022
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.3.2 – Arbitrary File Upload
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
*-1.3.3.2
1.3.3.3
04/06/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.