Drop Uploader for CF7 - Drag&Drop File Uploader Addon <= 2.4.1 - Unauthenticated Arbitrary File Upload
criticalThe Drop Uploader for CF7 - Drag&Drop File Uploader Addon plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may m...
- CVSS:
- 9.8
- Affected:
- up to 2.4.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 24, 2025