Input validation vulnerability in Drag and Drop Multiple File Upload – Contact Form 7 1.3.7.3

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is not secure in versions up to 1.3.7.3. This means that people without an account on the website can upload files to the server. These files can contain malicious code, which can be used to gain access to the website. To prevent this, people with editing privileges should make sure that the ‘multiple file upload’ form field only allows acceptable file types.

Detected in:

Drag and Drop Multiple File Upload – Contact Form 7 fixed vulnerable versions: >= * <= 1.3.7.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.