Drag and Drop Multiple File Upload for WooCommerce <= 1.1.7 - Unauthenticated Arbitrary File Deletion
critical
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files by first obtaining a valid nonce from the unauthenticated `wc_upload_nonce...
- CVSS:
- 9.1
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Jul 30, 2026
CVE-2026-16054 on NVD →
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
critical
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. T...
- CVSS:
- 9.8
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- May 8, 2025
CVE-2025-4403 on NVD →
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move
critical
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arbitrary files on the...
- CVSS:
- 9.8
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Apr 4, 2025
CVE-2025-2941 on NVD →
Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.0.9
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
- Disclosed:
- Dec 21, 2023
CVE-2022-45377 on NVD →
Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.1
unknown
[en] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Oct 16, 2023
CVE-2023-4821 on NVD →
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting
high
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious files (such as .svg) in versions up to, and including, 1.1.0 due to insufficient file type validation. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 7.2
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Sep 21, 2023
CVE-2023-4821 on NVD →
Drag and Drop Multiple File Upload for WooCommerce <= 1.0.8 - Cross-Site Request Forgery in upload and delete_file
high
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the upload and delete_file functions. This makes it possible for unauthenticated attackers to perform a...
- CVSS:
- 8.8
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.9
- Disclosed:
- Feb 24, 2023
CVE-2022-45377 on NVD →
Drag and Drop Multiple File Upload for WooCommerce <= 1.0.8 - Missing Authorization in upload and delete_file
medium
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload and delete_file functions in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber-level perm...
- CVSS:
- 6.5
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.9
- Disclosed:
- Feb 23, 2023
CVE-2022-45377 on NVD →
Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.5
unknown
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
CVE-2025-2941 on NVD →
Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.7
unknown
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
CVE-2025-4403 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database