Pricing
Case studies
Login
Start trial
Drag and Drop Multiple File Upload – Contact Form 7
Glen Don Mongaya
Developer
1.3.9.6
Latest version
60,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
15 patched
9 Mitigation rules
Unauthenticated Arbitrary File Upload vulnerability
<= 1.3.9.5
06/03/2026
Missing Authorization to Unauthenticated File Deletion vulnerability
<= 1.3.9.2
15/01/2026
WordPress Drag and Drop Multiple File Upload - Contact Form 7 plugin <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload vulnerability
<= 1.3.9.2
07/01/2026
Directory Traversal via `wpcf7_guest_user_id` Cookie vulnerability
<= 1.3.9.0
16/08/2025
Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks vulnerability
<= 1.3.8.9
17/06/2025
Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion vulnerability
<= 1.3.8.7
27/03/2025
Unauthenticated Arbitrary File Deletion vulnerability
<= 1.3.8.7
27/03/2025
Limited Arbitrary File Deletion vulnerability
<= 1.3.8.5
30/01/2025
Sensitive Information Exposure vulnerability
<= 1.3.7.7
30/04/2024
Wordpress Drag and Drop Multiple File Upload - Contact Form 7 plugin <= 1.3.7.3 - Unauthenticated Arbitrary File Upload vulnerability
<= 1.3.7.3
02/11/2023
Multiple CSRF vulnerabilities
<= 1.3.6.5
24/02/2023
File Upload Size Limit Bypass vulnerability
<= 1.3.6.4
26/09/2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 1.3.6.2
07/03/2022
Unauthenticated Remote Code Execution vulnerability
<= 1.3.5.4
21/09/2020
Unauthenticated File Upload vulnerability leading to Remote Code Execution (RCE)
<= 1.3.3.2
27/05/2020