Vulnerabilities > Codedropz > Drag AND Drop Multiple File Upload Contact Form 7 > 1.3.3.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-22 | CVE-2023-5822 | Unrestricted Upload of File with Dangerous Type vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. | 9.8 |
2023-05-24 | CVE-2022-45364 | Unspecified vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. | 8.8 |
2022-10-17 | CVE-2022-3282 | Authorization Bypass Through User-Controlled Key vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. | 4.3 |
2022-03-28 | CVE-2022-0595 | Unspecified vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue | 5.4 |
2020-06-08 | CVE-2020-12800 | Unrestricted Upload of File with Dangerous Type vulnerability in Codedropz Drag and Drop multiple File Upload - Contact Form 7 The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | 9.8 |