plugin

Drag N Drop Upload Cf7 Pro Vulnerabilities

6 known security issues reported for the Drag N Drop Upload Cf7 Pro WordPress plugin. Most recent disclosed Apr 17, 2023.

2 medium

Running Drag N Drop Upload Cf7 Pro on your site? Check whether your installed version is affected.

Scan your site free

Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 5.0.6.4

unknown

[en] The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a...

Affected:
up to 5.0.6.4
Fixed in:
5.0.6.4
Disclosed:
Apr 17, 2023

CVE-2023-1282 on NVD →

Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard <= 5.0.6.3 and <= 2.11.0 - Reflected Cross-Site Scripting

medium

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.0.6.3 or 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
2.0 – 2.11.0, 5.0 – 5.0.6.3
Fixed in:
2.11.1
Disclosed:
Mar 15, 2023

CVE-2023-1282 on NVD →

Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 2.11.1

unknown

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.0.6.3 or 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

Affected:
up to 2.11.1
Fixed in:
2.11.1
Disclosed:
Mar 15, 2023

Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 2.11.1

unknown

Update the WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin to the latest available version (at least 2.11.1). WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Drag and Drop Multiple File Upload PRO Plugin. This could allow a malicious actor to inject mali...

Affected:
up to 2.11.1
Fixed in:
2.11.1
Disclosed:
Mar 15, 2023

Drag and Drop Multiple File Upload PRO <= 2.10.9 - Directory Traversal

medium

The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.10.9 due to insufficient restrictions on the path supplied to the upload_dir value. This allows authenticated attackers to upload files to arbitrary locations on a webserver.

CVSS:
5.3
Affected:
up to 2.10.9
Fixed in:
2.11.0
Disclosed:
Mar 8, 2023

CVE-2023-1112 on NVD →

Drag & Drop Multiple File Upload CF7 Pro [drag-n-drop-upload-cf7-pro] < 5.0.6.4

unknown

[en] A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack rem...

Affected:
up to 5.0.6.4
Fixed in:
5.0.6.4
Disclosed:
Mar 1, 2023

CVE-2023-1112 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database