plugin

Drag And Drop Multiple File Upload For Woocommerce Vulnerabilities

10 known security issues reported for the Drag And Drop Multiple File Upload For Woocommerce WordPress plugin. Most recent disclosed Jul 30, 2026.

3 critical 2 high 1 medium

Running Drag And Drop Multiple File Upload For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.7 - Unauthenticated Arbitrary File Deletion

critical

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files by first obtaining a valid nonce from the unauthenticated `wc_upload_nonce...

CVSS:
9.1
Affected:
up to 1.1.7
Fixed in:
1.1.8
Disclosed:
Jul 30, 2026

CVE-2026-16054 on NVD →

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function

critical

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function. T...

CVSS:
9.8
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
May 8, 2025

CVE-2025-4403 on NVD →

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move

critical

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arbitrary files on the...

CVSS:
9.8
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Apr 4, 2025

CVE-2025-2941 on NVD →

Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.0.9

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Dec 21, 2023

CVE-2022-45377 on NVD →

Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.1

unknown

[en] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Oct 16, 2023

CVE-2023-4821 on NVD →

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting

high

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious files (such as .svg) in versions up to, and including, 1.1.0 due to insufficient file type validation. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
7.2
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Sep 21, 2023

CVE-2023-4821 on NVD →

Drag and Drop Multiple File Upload for WooCommerce <= 1.0.8 - Cross-Site Request Forgery in upload and delete_file

high

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the upload and delete_file functions. This makes it possible for unauthenticated attackers to perform a...

CVSS:
8.8
Affected:
up to 1.0.8
Fixed in:
1.0.9
Disclosed:
Feb 24, 2023

CVE-2022-45377 on NVD →

Drag and Drop Multiple File Upload for WooCommerce <= 1.0.8 - Missing Authorization in upload and delete_file

medium

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload and delete_file functions in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber-level perm...

CVSS:
6.5
Affected:
up to 1.0.8
Fixed in:
1.0.9
Disclosed:
Feb 23, 2023

CVE-2022-45377 on NVD →

Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.5

unknown
Affected:
up to 1.1.5
Fixed in:
1.1.5

CVE-2025-2941 on NVD →

Drag and Drop Multiple File Upload for WooCommerce [drag-and-drop-multiple-file-upload-for-woocommerce] < 1.1.7

unknown
Affected:
up to 1.1.7
Fixed in:
1.1.7

CVE-2025-4403 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database