Lucene search

K
patchstackAustin MartinPATCHSTACK:3A7BD2C24FAC5B7B181DE0E523CEFE21
HistoryMay 27, 2020 - 12:00 a.m.

WordPress Drag and Drop Multiple File Upload for Contact Form 7 plugin <= 1.3.3.2 - Unauthenticated File Upload vulnerability leading to Remote Code Execution (RCE)

2020-05-2700:00:00
Austin Martin
patchstack.com
8

0.974 High

EPSS

Percentile

99.9%

Unauthenticated File Upload vulnerability leading to Remote Code Execution (RCE) discovered by Austin Martin in WordPress Drag and Drop Multiple File Upload for Contact Form 7 plugin (versions <= 1.3.3.2).

Solution

           Update the WordPress Drag and Drop Multiple File Upload for Contact Form 7 plugin to the latest available version (at least 1.3.3.3).