Input validation vulnerability in Drag and Drop Multiple File Upload for WooCommerce 1.1.6

The plugin called “Drag and Drop Multiple File Upload” for the website platform WordPress has a security issue that allows hackers to upload any type of file onto the site. This can be done by using a specific string of characters and file name when uploading. This vulnerability affects all versions up to 1.1.6 and could potentially lead to hackers being able to execute code remotely on the site’s server.

Detected in:

Drag and Drop Multiple File Upload for WooCommerce fixed vulnerable versions: >= * <= 1.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.