PT-2025-33542 · WordPress · Drag/Drop Multiple File Upload – Contact Form 7

Thien Tran

·

Published

2025-08-16

·

Updated

2025-08-16

·

CVE-2025-8464

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress versions through 1.3.9.0
Description: The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal via the wpcf7 guest user id cookie. This allows unauthenticated attackers to upload and delete files outside of the originally intended directory. File type validation limits uploads to safe file types, and deletion is restricted to the plugin's uploads folder.
Recommendations: Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to a version later than 1.3.9.0.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-8464

Affected Products

Drag/Drop Multiple File Upload – Contact Form 7