Input validation vulnerability in Drag and Drop Multiple File Upload for Contact Form 7 1.3.8.7

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress has a security issue that could allow attackers to inject harmful code through a process called deserialization. This vulnerability can only be exploited if another plugin or theme with a specific code is also installed on the website. This could potentially lead to unauthorized actions such as deleting files, accessing sensitive information, or running malicious code. In order for this vulnerability to be exploited, the Flamingo plugin must also be installed and activated.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.