Drag and Drop Multiple File Upload – Contact Form 7, CVE-2020-12800
- CVE, Research URL
- Published on
- Jun 08, 2020
- Research Description
- The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
- Affected versions
-
Min -, max 1.3.3.3.
- Status
-
vulnerable