CVE-2026-5718
Drag and Drop Multiple File Upload for Contact Form 7
Minimum safe version
1.3.9.7
Update to 1.3.9.7 or later to address 19 fixable vulnerabilities
CVE-2026-5710
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitrary File Upload
CVE-2025-14457
CVE-2025-14842
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion
CVE-2024-12267
CVE-2024-3717
CVE-2023-5822
CVE-2022-45364
CVE-2020-24389
CVE-2022-3282
WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.5.4 - Unauthenticated Remote Code Execution vulnerability
CVE-2022-0595
CVE-2020-12800