WordPress Contact Form 7 before 1.3.6.3 contains an unauthenticated stored cross-site scripting vulnerability in the Drag and Drop Multiple File Upload plugin. SVG files can be uploaded by default via the dnd_codedropz_upload AJAX action.
id: CVE-2022-0595
info:
name: WordPress Contact Form 7 <1.3.6.3 - Stored Cross-Site Scripting
a
...