Vulnerabilities > Codedropz

DATE CVE VULNERABILITY TITLE RISK
2023-12-21 CVE-2022-45377 Unrestricted Upload of File with Dangerous Type vulnerability in Codedropz Drag and Drop multiple File Upload for Woocommerce
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L.
network
low complexity
codedropz CWE-434
critical
9.8
2023-11-22 CVE-2023-5822 Unrestricted Upload of File with Dangerous Type vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3.
network
low complexity
codedropz CWE-434
critical
9.8
2023-10-16 CVE-2023-4821 Unspecified vulnerability in Codedropz Drag and Drop multiple File Uploader
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions.
network
low complexity
codedropz
5.4
2023-05-24 CVE-2022-45364 Cross-Site Request Forgery (CSRF) vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L.
network
low complexity
codedropz CWE-352
8.8
2023-04-17 CVE-2023-1282 Unspecified vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 5.0.6.1/5.0.6.3
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.
network
low complexity
codedropz
6.1
2023-03-01 CVE-2023-1112 Path Traversal vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 5.0.6.1
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress.
network
low complexity
codedropz CWE-22
critical
9.8
2022-10-17 CVE-2022-3282 Authorization Bypass Through User-Controlled Key vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form.
network
low complexity
codedropz CWE-639
4.3
2022-03-28 CVE-2022-0595 Cross-site Scripting vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
network
low complexity
codedropz CWE-79
5.4
2020-06-08 CVE-2020-12800 Unrestricted Upload of File with Dangerous Type vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
network
low complexity
codedropz CWE-434
critical
9.8