plugin

Drag And Drop File Upload For Contact Form 7 Vulnerabilities

1 known security issue reported for the Drag And Drop File Upload For Contact Form 7 WordPress plugin. Most recent disclosed Apr 23, 2026.

1 high

Running Drag And Drop File Upload For Contact Form 7 on your site? Check whether your installed version is affected.

Scan your site free

Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass

high

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being...

CVSS:
8.1
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Apr 23, 2026

CVE-2026-5364 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database