Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Drag and Drop Multiple File Upload for Contact Form 7 — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Drag and Drop Multiple File Upload for Contact Form 7, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregation for the Drag and Drop Multiple File Upload for Contact Form 7 plugin, specifically focusing on weaknesses associated with file upload handling. The content here compiles a comprehensive list of identified security flaws, including those related to unvalidated file types, insufficient server-side checks, and potential remote code execution vectors introduced through the drag-and-drop interface. This collection covers incidents discovered and reported over the last several years, providing a historical perspective on the plugin’s security posture. By reviewing this data, researchers and administrators can track advisory patterns from the vendor to understand how quickly threats are mitigated. Users can also gain a deeper understanding of specific weakness classes, such as Improper Input Validation, by seeing how they manifest in this particular codebase. Furthermore, this resource allows for a detailed look-up of the product’s vulnerability history, highlighting recurring issues that may indicate systemic architectural problems. It serves as a neutral repository for analyzing risk trends without editorial bias, enabling informed decisions regarding plugin updates, patching schedules, and alternative selection. The data supports proactive security management by revealing whether vulnerabilities were addressed in subsequent releases or if certain flaws have persisted across multiple versions, ultimately helping organizations assess their exposure to known exploits associated with this widely used WordPress extension.

Vendor: glenwpcoder

CVE IDTitleCVSSSeverityPublished
CVE-2026-5710 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field CWE-22 7.5 High2026-04-17
CVE-2026-5718 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass CWE-434 8.1 High2026-04-17
CVE-2026-3459 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High2026-03-05
CVE-2025-14457 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion CWE-862 3.7 Low2026-01-15
CVE-2025-14842 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload CWE-434 6.1 Medium2026-01-07
CVE-2025-8464 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie CWE-23 5.3 Medium2025-08-16
CVE-2025-3515 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks CWE-434 8.1 High2025-06-17
CVE-2025-2485 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion CWE-502 7.5 High2025-03-28
CVE-2025-2328 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion CWE-22 8.8 High2025-03-28
CVE-2024-12267 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion CWE-73 5.3 Medium2025-01-31
CVE-2024-3717 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure CWE-922 5.3 Medium2024-05-02
CVE-2023-5822 Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload CWE-434 8.1 High2023-11-22

All 12 known CVE vulnerabilities affecting Drag and Drop Multiple File Upload for Contact Form 7 with full Chinese analysis, references, and POCs where available.