The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary w [truncated]
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin contains an arbitrary file upload vulnerability affecting versions up to and including 1.3.9.7. The flaw stems from two weaknesses: insufficient file type validation when custom blacklist types are configured (which replaces rather than merges with the default dangerous extension denylist), and a bypass of the wpcf7_antiscript_file [truncated]
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type. This makes it possible for unauthenticated attackers to upload arbitrary .phar or .svg files containing malicious PHP or JavaScript code. The vulnerability exists in all versions up to, and including, 1.3.9.2 due to the plugin not blocking .phar and .svg files. Defen [truncated]