Description
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
Published: 2026-01-15
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Data Deletion / Integrity
Action: Upgrade Plugin
AI Analysis

Impact

The Drag and Drop Multiple File Upload for Contact Form 7 plugin contains a missing ownership check in its delete functionality. Unauthenticated users can invoke the delete routine to remove any uploaded file when the "Send attachments as links" feature is turned on. This flaw allows unauthorized deletion of user‑supplied attachments, compromising data integrity and potentially disrupting site operations.

Affected Systems

Versions of the plugin up to and including 1.3.9.2, distributed through WordPress, are affected. The vulnerable component is the dnd_codedropz_upload_delete() function, part of the Drag and Drop Multiple File Upload for Contact Form 7 plugin authored by glenwpcoder. Any WordPress installation that has this plugin installed and the "Send attachments as links" option enabled is susceptible.

Risk and Exploitability

The vulnerability scores a CVSS of 3.7, indicating a low‑to‑moderate severity. The EPSS score is reported as < 1%, suggesting a very low likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. An attacker can trigger the deletion by sending an unauthenticated request to the plugin’s delete endpoint; no special privileges or additional conditions beyond the enabled setting are required. The primary impact is loss of uploaded files, which may impact user experience and site functionality, but there is no direct path to code execution or data exfiltration.

Generated by OpenCVE AI on April 22, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drag and Drop Multiple File Upload for Contact Form 7 to a version newer than 1.3.9.2
  • If an upgrade cannot be performed immediately, disable the "Send attachments as links" setting or remove the plugin from the WordPress installation to prevent unauthenticated delete attempts
  • Implement server‑side file access controls or custom logic to enforce ownership checks before allowing file deletion

Generated by OpenCVE AI on April 22, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 23 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Codedropz contact Form 7
CPEs cpe:2.3:a:codedropz:contact_form_7:*:*:*:*:*:wordpress:*:*
Vendors & Products Codedropz contact Form 7

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Codedropz
Codedropz drag And Drop Multiple File Upload - Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Codedropz
Codedropz drag And Drop Multiple File Upload - Contact Form 7
Wordpress
Wordpress wordpress

Thu, 15 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
Title Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Codedropz Contact Form 7 Drag And Drop Multiple File Upload - Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:37:59.291Z

Reserved: 2025-12-10T14:55:41.035Z

Link: CVE-2025-14457

cve-icon Vulnrichment

Updated: 2026-01-15T14:47:42.600Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-15T07:16:02.717

Modified: 2026-01-23T15:56:08.487

Link: CVE-2025-14457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T15:45:20Z

Weaknesses