PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14325 Drag and Drop Multiple File Upload for Contact Form 7 CVE debrief

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output. This allows users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. The vulnerability was published on 2026-08-21T07:16:24.430Z. Administrators and users of the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin should verify and update to version 1.3.9.9 or later if necessary. Limited information is available about affected products and versions.

Vendor
Drag and Drop Multiple File Upload for Contact Form 7
Product
Drag and Drop Multiple File Upload for Contact Form 7
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Administrators and users of the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin, especially those with administrator access, should verify and update to version 1.3.9.9 or later if necessary. They should also review compensating controls for exposed systems and monitor front-end pages rendering the upload field for potential web script injection. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their systems and take necessary precautions to prevent exploitation. Asset inventory and patch management teams should also prioritize updating affected systems to prevent potential attacks. This vulnerability can be mitigated by updating to version 1.3.9.9 or later and monitoring affected systems. Security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Asset inventory and patch management teams should prioritize updating affected systems to prevent potential attacks. Source tracking and monitoring should be implemented to detect potential exploitation attempts. Rollback/change windows should be planned to minimize downtime and ensure smooth remediation. Security teams should also consider implementing additional security measures such as web application firewalls and intrusion detection systems to detect and prevent potential attacks. They should also review and update their incident response plans to include procedures for responding to potential exploitation of this vulnerability. By taking these precautions, organizations can minimize the risk of exploitation and protect their systems from potential attacks. Security teams should also consider conducting a thorough risk assessment to identify,

Technical summary

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. This vulnerability can be mitigated by updating to version 1.3.9.9 or later and monitoring affected systems.

Defensive priority

Administrators using the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin should verify and update to version 1.3.9.9 or later.

Recommended defensive actions

  • Verify the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin version and update to 1.3.9.9 or later if necessary.
  • Monitor front-end pages rendering the upload field for potential web script injection.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE record indicates the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output. Limited information is available about affected products and versions. Administrators should verify the plugin version and update to 1.3.9.9 or later if necessary. They should also monitor front-end pages rendering the upload field for potential web script injection and review compensating controls for exposed systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T07:16:24.430Z and has not been modified since then.