Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Thien Tran

#50712of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2025-33542
5.3
2025-08-16
WordPress · Drag/Drop Multiple File Upload – Contact Form 7 · CVE-2025-8464
Name of the Vulnerable Software and Affected Versions: Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress versions through 1.3.9.0 Description: The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal via the `wpcf7 guest user id` cookie. This allows unauthenticated attackers to upload and delete files outside of the originally intended directory. File type validation limits uploads to safe file types, and deletion is restricted to the plugin's uploads folder. Recommendations: Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to a version later than 1.3.9.0.