← WordPress Vulnerabilities
WordPress security by component

Drag and Drop Multiple File Upload for Contact Form 7

Drag and Drop Multiple File Upload for Contact Form 7 is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jan 15, 2026; the highest CVE/CNA score is 10.

Plugin slug: contact-form-7

CVE-2025-14457: Drag and Drop Multiple File Upload for Contact Form 7: A security weakness

Drag and Drop Multiple File Upload for Contact Form 7 is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 15, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 15, 2026 CVE-2025-14457
Drag and Drop Multiple File Upload for Contact Form 7: A security weakness
Drag and Drop Multiple File Upload for Contact Form 7 is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.7
NVD7.4
Jan 07, 2026 CVE-2025-14842
Drag and Drop Multiple File Upload – Contact Form 7: Cross-site scripting
Drag and Drop Multiple File Upload – Contact Form 7 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 16, 2025 CVE-2025-3247
Contact Form 7: A security weakness
Contact Form 7 is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jun 27, 2024 CVE-2024-4704
Contact Form 7: An open redirect
Contact Form 7 is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE6.1
NVD6.1
Mar 13, 2024 CVE-2024-2242
Contact Form 7: Cross-site scripting
Contact Form 7 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jan 11, 2024 CVE-2023-6630
Contact Form 7 – Dynamic Text Extension: A security weakness
Contact Form 7 – Dynamic Text Extension is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Dec 01, 2023 CVE-2023-6449
Contact Form 7: Dangerous file upload
Contact Form 7 is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE6.6
NVD7.2
Apr 05, 2021 CVE-2021-24159
custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style: A security weakness
custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Dec 17, 2020 CVE-2020-35489
Contact Form 7: Code execution
Contact Form 7 is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE10.0
NVD10.0
Aug 22, 2019 CVE-2018-20979
Contact Form 7: Privilege escalation or authentication bypass
Contact Form 7 is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
Mar 14, 2014 CVE-2014-2265
Contact Form 7: A security weakness
Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0