Input validation vulnerability in Drag and Drop Multiple File Upload (Pro) – WooCommerce 1.7.1

The Drag and Drop Multiple File Upload (Pro) – WooCommerce plugin for WordPress is at risk of allowing unauthorized file uploads. This is because it does not properly check the type of file being uploaded in the dnd_upload_cf7_upload_chunks() function. This vulnerability affects versions 5.0 – 5.0.5 (when used with the PrintSpace theme) and all versions up to, and including, 1.7.1 (in the standalone version). This means that hackers without proper authorization could upload harmful files to the website’s server, potentially allowing them to take control of the site. While PHP execution is typically blocked, it may still be possible in some cases.

Detected in:

Drag and Drop Multiple File Upload (Pro) - WooCommerce fixed vulnerable versions: >= * <= 1.7.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.