Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 5.0.6.4
unknown
[en] The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a...
- Affected:
- up to 5.0.6.4
- Fixed in:
- 5.0.6.4
- Disclosed:
- Apr 17, 2023
CVE-2023-1282 on NVD →
Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard <= 5.0.6.3 and <= 2.11.0 - Reflected Cross-Site Scripting
medium
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.0.6.3 or 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- 2.0 – 2.11.0, 5.0 – 5.0.6.3
- Fixed in:
- 2.11.1
- Disclosed:
- Mar 15, 2023
CVE-2023-1282 on NVD →
Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 2.11.1
unknown
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.0.6.3 or 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Mar 15, 2023
Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 2.11.1
unknown
Update the WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin to the latest available version (at least 2.11.1).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Drag and Drop Multiple File Upload PRO Plugin. This could allow a malicious actor to inject mali...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Mar 15, 2023
Drag and Drop Multiple File Upload PRO <= 2.10.9 - Directory Traversal
medium
The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.10.9 due to insufficient restrictions on the path supplied to the upload_dir value. This allows authenticated attackers to upload files to arbitrary locations on a webserver.
- CVSS:
- 5.3
- Affected:
- up to 2.10.9
- Fixed in:
- 2.11.0
- Disclosed:
- Mar 8, 2023
CVE-2023-1112 on NVD →
Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 5.0.6.4
unknown
[en] A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack rem...
- Affected:
- up to 5.0.6.4
- Fixed in:
- 5.0.6.4
- Disclosed:
- Mar 1, 2023
CVE-2023-1112 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database