Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Thien Tran

#48355of 53,632
5.3Total CVSS
Vulnerabilities · 1
PT-2025-33542
5.3
2025-08-16
WordPress · Drag/Drop Multiple File Upload – Contact Form 7 · CVE-2025-8464
Name of the Vulnerable Software and Affected Versions: Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress versions through 1.3.9.0 Description: The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal via the `wpcf7 guest user id` cookie. This allows unauthenticated attackers to upload and delete files outside of the originally intended directory. File type validation limits uploads to safe file types, and deletion is restricted to the plugin's uploads folder. Recommendations: Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to a version later than 1.3.9.0.