Input validation vulnerability in Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard 2.11.0

The Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard plugin for WordPress is not safe to use. It has a security issue called Reflected Cross-Site Scripting which could allow unauthenticated attackers to insert malicious web scripts into pages. This happens because the plugin does not properly check and protect inputs and outputs. It can be exploited if a user is tricked into doing something like clicking on a link. Note that this plugin has multiple versions and they all have the same name.

Detected in:

Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard fixed vulnerable versions: >= 2.0 <= 2.11.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.