PT-2024-27354 · WordPress · Drag/Drop Multiple File Upload – Contact Form 7

Tim Coen

·

Published

2024-05-02

·

Updated

2025-08-08

·

CVE-2024-3717

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress versions up to, and including, 1.3.7.7
Description The issue allows unauthenticated attackers to extract sensitive data uploaded via the plugin through a form. This is possible due to the exposure of sensitive information in the '/wp-content/uploads/wp dndcf7 uploads/wpcf7-files' directory.
Recommendations For versions up to, and including, 1.3.7.7, update to a version later than 1.3.7.7 to resolve the issue. As a temporary workaround, consider restricting access to the '/wp-content/uploads/wp dndcf7 uploads/wpcf7-files' directory to minimize the risk of exploitation.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-3717

Affected Products

Drag/Drop Multiple File Upload – Contact Form 7