plugin

Drag And Drop Multiple File Upload Contact Form 7 Vulnerabilities

37 known security issues reported for the Drag And Drop Multiple File Upload Contact Form 7 WordPress plugin. Most recent disclosed Aug 24, 2026.

3 critical 10 high 7 medium 1 low

Running Drag And Drop Multiple File Upload Contact Form 7 on your site? Check whether your installed version is affected.

Scan your site free

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated Remote Code Execution

critical

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.3.9.9. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for unauthenticated attackers to execute arbitrary code on the...

CVSS:
9.8
Affected:
up to 1.3.9.9
Fixed in:
1.3.9.9
Disclosed:
Aug 24, 2026

CVE-2026-18781 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 1.3.9.9. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to...

CVSS:
4.4
Affected:
up to 1.3.9.9
Fixed in:
1.3.9.9
Disclosed:
Aug 24, 2026

CVE-2026-14325 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings

medium

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for a...

CVSS:
4.4
Affected:
up to 1.3.9.7
Fixed in:
1.3.9.8
Disclosed:
Jun 5, 2026

CVE-2026-8991 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Stored Cross-Site Scripting

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
7.2
Affected:
up to 1.3.9.7
Fixed in:
1.3.9.8
Disclosed:
Jun 3, 2026

CVE-2026-49055 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylis...

CVSS:
8.1
Affected:
up to 1.3.9.7
Fixed in:
1.3.9.8
Disclosed:
Apr 17, 2026

CVE-2026-5718 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without perform...

CVSS:
7.5
Affected:
up to 1.3.9.6
Fixed in:
1.3.9.7
Disclosed:
Apr 17, 2026

CVE-2026-5710 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 - Unauthenticated Arbitrary File Upload vulnerability

critical

Unauthenticated Arbitrary File Upload vulnerability

CVSS:
10
Affected:
up to 1.3.9.5
Fixed in:
1.3.9.6
Disclosed:
Mar 6, 2026

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload

high

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files...

CVSS:
8.1
Affected:
up to 1.3.9.5
Fixed in:
1.3.9.6
Disclosed:
Mar 5, 2026

CVE-2026-3459 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.9.3

unknown

[en] The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to del...

Affected:
up to 1.3.9.3
Fixed in:
1.3.9.3
Disclosed:
Jan 15, 2026

CVE-2025-14457 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion

low

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete a...

CVSS:
3.7
Affected:
up to 1.3.9.2
Fixed in:
1.3.9.3
Disclosed:
Jan 14, 2026

CVE-2025-14457 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.9.3

unknown

[en] The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload arbi...

Affected:
up to 1.3.9.3
Fixed in:
1.3.9.3
Disclosed:
Jan 7, 2026

CVE-2025-14842 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload

medium

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload arbitrary...

CVSS:
6.1
Affected:
up to 1.3.9.2
Fixed in:
1.3.9.3
Disclosed:
Jan 6, 2026

CVE-2025-14842 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie

medium

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directo...

CVSS:
5.3
Affected:
up to 1.3.9.0
Fixed in:
1.3.9.1
Disclosed:
Aug 15, 2025

CVE-2025-8464 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other d...

CVSS:
8.1
Affected:
up to 1.3.8.9
Fixed in:
1.3.9.0
Disclosed:
Jun 16, 2025

CVE-2025-3515 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated attackers to add arbitrar...

CVSS:
8.8
Affected:
up to 1.3.8.7
Fixed in:
1.3.8.8
Disclosed:
Mar 27, 2025

CVE-2025-2328 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion

high

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for attackers to inject a PHP Object through a PHA...

CVSS:
7.5
Affected:
up to 1.3.8.8
Fixed in:
1.3.8.9
Disclosed:
Mar 27, 2025

CVE-2025-2485 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.8.6

unknown

[en] The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to...

Affected:
up to 1.3.8.6
Fixed in:
1.3.8.6
Disclosed:
Jan 31, 2025

CVE-2024-12267 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion

medium

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to dele...

CVSS:
5.3
Affected:
up to 1.3.8.5
Fixed in:
1.3.8.6
Disclosed:
Jan 30, 2025

CVE-2024-12267 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.7.8

unknown

[en] The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive...

Affected:
up to 1.3.7.8
Fixed in:
1.3.7.8
Disclosed:
May 2, 2024

CVE-2024-3717 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure

medium

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive data...

CVSS:
5.3
Affected:
up to 1.3.7.7
Fixed in:
1.3.7.8
Disclosed:
Apr 29, 2024

CVE-2024-3717 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.7.4

unknown

[en] The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files...

Affected:
up to 1.3.7.4
Fixed in:
1.3.7.4
Disclosed:
Nov 22, 2023

CVE-2023-5822 on NVD →

Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload

high

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files...

CVSS:
8.1
Affected:
up to 1.3.7.3
Fixed in:
1.3.7.4
Disclosed:
Nov 1, 2023

CVE-2023-5822 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.6.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

Affected:
up to 1.3.6.6
Fixed in:
1.3.6.6
Disclosed:
May 24, 2023

CVE-2022-45364 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.5 - Cross-Site Request Forgery in dnd_upload_cf7_upload and dnd_codedropz_upload_delete

high

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.6.5. This is due to missing or incorrect nonce validation on the dnd_upload_cf7_upload and dnd_codedropz_upload_delete functions. This makes it possible for unau...

CVSS:
8.8
Affected:
up to 1.3.6.5
Fixed in:
1.3.6.6
Disclosed:
Feb 24, 2023

CVE-2022-45364 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.6.5

unknown

[en] The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

Affected:
up to 1.3.6.5
Fixed in:
1.3.6.5
Disclosed:
Oct 17, 2022

CVE-2022-3282 on NVD →

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.4 - File Upload Size Limit Bypass

medium

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to File Upload Size Limit Bypass in versions up to, and including, 1.3.6.4. This is due to the plugin accepting the file size limit as a POST parameter. This makes it possible for attackers to upload large files.

CVSS:
5.3
Affected:
up to 1.3.6.4
Fixed in:
1.3.6.5
Disclosed:
Sep 26, 2022

CVE-2022-3282 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.6.3

unknown

[en] The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

Affected:
up to 1.3.6.3
Fixed in:
1.3.6.3
Disclosed:
Mar 28, 2022

CVE-2022-0595 on NVD →

Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.6.2 - Unauthenticated Stored Cross-Site Scripting

high

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVSS:
7.2
Affected:
up to 1.3.6.2
Fixed in:
1.3.6.3
Disclosed:
Mar 7, 2022

CVE-2022-0595 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.5.5

unknown

Unauthenticated Remote Code Execution vulnerability found in WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin (versions <= 1.3.5.4).

Affected:
up to 1.3.5.5
Fixed in:
1.3.5.5
Disclosed:
Sep 21, 2020

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.3.3

unknown

[en] The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

Affected:
up to 1.3.3.3
Fixed in:
1.3.3.3
Disclosed:
Jun 8, 2020

CVE-2020-12800 on NVD →

Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.3.2 - Arbitrary File Upload

critical

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

CVSS:
9.8
Affected:
up to 1.3.3.2
Fixed in:
1.3.3.3
Disclosed:
Jun 4, 2020

CVE-2020-12800 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.8.8

unknown
Affected:
up to 1.3.8.8
Fixed in:
1.3.8.8

CVE-2025-2328 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.8.8

unknown
Affected:
up to 1.3.8.8
Fixed in:
1.3.8.8

CVE-2025-2485 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.9.0

unknown
Affected:
up to 1.3.9.0
Fixed in:
1.3.9.0

CVE-2025-3515 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.9.1

unknown
Affected:
up to 1.3.9.1
Fixed in:
1.3.9.1

CVE-2025-8464 on NVD →

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.8.6

unknown

The Drag and Drop Multiple File Upload &ndash; Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers t...

Affected:
up to 1.3.8.6
Fixed in:
1.3.8.6

Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] < 1.3.5.5

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.3.5.5
Fixed in:
1.3.5.5

CVE-2020-24389 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database