Access violation vulnerability in Drag and Drop Multiple File Upload for Contact Form 7 1.3.8.7

A plugin called “Drag and Drop Multiple File Upload for Contact Form 7” used on WordPress websites has a security issue. It doesn’t check file paths properly, which means someone could delete important files on the website. This could let hackers run malicious code on the website if an administrator deletes a certain message. To use this vulnerability, the website also needs to have another plugin called “Flamingo” installed and active.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.