PatchSiren

glenwpcoder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM glenwpcoder CVE published 2026-06-06

CVE-2026-8991

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary w [truncated]

HIGH glenwpcoder CVE published 2026-04-17

CVE-2026-5718

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin contains an arbitrary file upload vulnerability affecting versions up to and including 1.3.9.7. The flaw stems from two weaknesses: insufficient file type validation when custom blacklist types are configured (which replaces rather than merges with the default dangerous extension denylist), and a bypass of the wpcf7_antiscript_file [truncated]

MEDIUM glenwpcoder CVE published 2026-01-07

CVE-2025-14842

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type. This makes it possible for unauthenticated attackers to upload arbitrary .phar or .svg files containing malicious PHP or JavaScript code. The vulnerability exists in all versions up to, and including, 1.3.9.2 due to the plugin not blocking .phar and .svg files. Defen [truncated]