Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Drag and Drop Multiple File Upload for Contact Form 7 — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Drag and Drop Multiple File Upload for Contact Form 7, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the WordPress plugin "Drag and Drop Multiple File Upload for Contact Form 7," published by the developer 10up. It collects historical and recent advisories related to this specific product, covering its full vulnerability history across various weakness types such as improper file upload handling and path traversal. Readers can use this resource to track the vendor’s security advisories, understand recurring weakness classes in file upload functionality, and review the product’s documented vulnerability history. The collection spans the period from the plugin’s initial release through the most recently identified issues, providing a chronological view of its security posture. The entries link to detailed reports describing each flaw, its impact, and the available remediation. This aggregation serves as a reference for security teams evaluating the plugin’s risk profile or researchers studying how file upload weaknesses have evolved within this specific Contact Form 7 extension.

Vendor: glenwpcoder

CVE ID Title CVSS Severity Published
CVE-2026-18781 Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass - - 2026-08-21
CVE-2026-14325 Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting - - 2026-08-21
CVE-2026-8991 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings CWE-79 4.4 Medium 2026-06-06
CVE-2026-5710 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field CWE-22 7.5 High 2026-04-17
CVE-2026-5718 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass CWE-434 8.1 High 2026-04-17
CVE-2026-3459 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High 2026-03-05
CVE-2025-14457 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion CWE-862 3.7 Low 2026-01-15
CVE-2025-14842 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload CWE-434 6.1 Medium 2026-01-07
CVE-2025-8464 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie CWE-23 5.3 Medium 2025-08-16
CVE-2025-3515 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks CWE-434 8.1 High 2025-06-17
CVE-2025-2485 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion CWE-502 7.5 High 2025-03-28
CVE-2025-2328 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion CWE-22 8.8 High 2025-03-28
CVE-2024-12267 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion CWE-73 5.3 Medium 2025-01-31
CVE-2024-3717 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure CWE-922 5.3 Medium 2024-05-02
CVE-2023-5822 Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High 2023-11-22

All 15 known CVE vulnerabilities affecting Drag and Drop Multiple File Upload for Contact Form 7 with full Chinese analysis, references, and POCs where available.