WordPress插件 Contact Form 7 的“拖放多文件上传”功能(版本低于1.3.9.9)存在一个漏洞:该插件在将其某个设置值作为HTML标签名称用于前端输出之前,未对该设置进行转义处理。这允许拥有管理员权限的用户注入任意Web脚本,这些脚本将在任何包含该上传字段的前端页面渲染时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Drag and Drop Multiple File Upload for Contact Form 7 | < 1.3.9.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Drag and Drop Multiple File Upload for Contact Form 7 | 0 ~ 1.3.9.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19848 | 6.5 MEDIUM | ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name |
| CVE-2026-17559 | 5.3 MEDIUM | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via RE |
| CVE-2026-16650 | 5.3 MEDIUM | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webh |
| CVE-2026-15150 | 5.3 MEDIUM | myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verificati |
| CVE-2026-15046 | 4.2 MEDIUM | LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRF |
| CVE-2026-18356 | 3.7 LOW | Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Acco |
| CVE-2026-13176 | 2.7 LOW | Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery |
| CVE-2026-13736 | NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII D | |
| CVE-2025-15671 | Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter | |
| CVE-2026-14601 | Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter | |
| CVE-2026-16576 | Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API | |
| CVE-2026-16962 | Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation | |
| CVE-2026-16575 | Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST | |
| CVE-2026-19085 | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure | |
| CVE-2026-19435 | Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure | |
| CVE-2026-18781 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via | |
| CVE-2026-16959 | Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector | |
| CVE-2026-16577 | Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount | |
| CVE-2026-75796 | AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP |
No comments yet