cleantalk
Vulnerabilities and Security Researches

Drag and Drop Multiple File Upload – Contact Form 7, CVE-2020-12800

CVE, Research URL

CVE-2020-12800

Published on
Jun 08, 2020
Research Description
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
Affected versions
Min -, max 1.3.3.3.
Status
vulnerable