PT-2025-25642 · Contact Form 7 · Drag/Drop Multiple File Upload – Contact Form 7

Michael Mazzolini

·

Published

2025-06-17

·

Updated

2025-08-30

·

CVE-2025-3515

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Drag and Drop Multiple File Upload for Contact Form 7 versions through 1.3.8.9

**Description:**

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation. This allows unauthenticated attackers to circumvent the plugin’s blacklist and upload potentially dangerous file types, such as `.phar` files, to the affected server. In environments configured to execute `.phar` files as PHP scripts—particularly those using default Apache+mod php configurations—this could lead to remote code execution.

**Recommendations:**

Versions prior to 1.3.8.9 are affected.

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-3515

Affected Products

Drag/Drop Multiple File Upload – Contact Form 7