PatchSiren cyber security CVE debrief
CVE-2026-14325 Drag and Drop Multiple File Upload for Contact Form 7 CVE debrief
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output. This allows users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. The vulnerability was published on 2026-08-21T07:16:24.430Z. Administrators and users of the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin should verify and update to version 1.3.9.9 or later if necessary. Limited information is available about affected products and versions.
- Vendor
- Drag and Drop Multiple File Upload for Contact Form 7
- Product
- Drag and Drop Multiple File Upload for Contact Form 7
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin, especially those with administrator access, should verify and update to version 1.3.9.9 or later if necessary. They should also review compensating controls for exposed systems and monitor front-end pages rendering the upload field for potential web script injection. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their systems and take necessary precautions to prevent exploitation. Asset inventory and patch management teams should also prioritize updating affected systems to prevent potential attacks. This vulnerability can be mitigated by updating to version 1.3.9.9 or later and monitoring affected systems. Security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Asset inventory and patch management teams should prioritize updating affected systems to prevent potential attacks. Source tracking and monitoring should be implemented to detect potential exploitation attempts. Rollback/change windows should be planned to minimize downtime and ensure smooth remediation. Security teams should also consider implementing additional security measures such as web application firewalls and intrusion detection systems to detect and prevent potential attacks. They should also review and update their incident response plans to include procedures for responding to potential exploitation of this vulnerability. By taking these precautions, organizations can minimize the risk of exploitation and protect their systems from potential attacks. Security teams should also consider conducting a thorough risk assessment to identify,
Technical summary
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. This vulnerability can be mitigated by updating to version 1.3.9.9 or later and monitoring affected systems.
Defensive priority
Administrators using the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin should verify and update to version 1.3.9.9 or later.
Recommended defensive actions
- Verify the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin version and update to 1.3.9.9 or later if necessary.
- Monitor front-end pages rendering the upload field for potential web script injection.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record indicates the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output. Limited information is available about affected products and versions. Administrators should verify the plugin version and update to 1.3.9.9 or later if necessary. They should also monitor front-end pages rendering the upload field for potential web script injection and review compensating controls for exposed systems.
Official resources
-
CVE-2026-14325 CVE record
CVE.org
-
CVE-2026-14325 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T07:16:24.430Z and has not been modified since then.