Description
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-06-06
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Drag and Drop Multiple File Upload for Contact Form 7 plugin allows an administrator or higher level user to insert arbitrary text into the drag_n_drop_text and drag_n_drop_browse_text settings. Because the input is not properly sanitized or escaped, the inserted content is stored and later rendered on pages that use the plugin. When a user visits a page containing the injected settings, a browser will execute the malicious script, enabling an attacker to steal session cookies, hijack accounts, deface content, or redirect to phishing sites. The vulnerability does not provide arbitrary code execution on the server, but it allows client‑side script injection that can compromise user confidentiality and the integrity of web pages.

Affected Systems

WordPress sites using the glenwpcoder Drag and Drop Multiple File Upload for Contact Form 7 plugin in any version up to and including 1.3.9.7 are affected. Administrators with access to the plugin settings are required to inject malicious text, so the threat requires authenticated elevated access within the WordPress installation.

Risk and Exploitability

The CVSS score of 4.4 reflects moderate risk. EPSS is not available, but given the need for administrator access the likelihood of exploitation is low in environments with strong role separation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploitation. Attackers would need to compromise a user with administrative privileges, modify the plugin settings to inject scripts, and then rely on unsuspecting visitors to trigger the stored XSS when they load affected pages.

Generated by OpenCVE AI on June 6, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Drag and Drop Multiple File Upload for Contact Form 7 plugin to the newest available version that removes unsanitized input handling.
  • If an upgrade is not immediately possible, disable or uninstall the plugin entirely, or an alternate file‑upload solution that does not store arbitrary text in its configuration.
  • Modify the drag_n_drop_text and drag_n_drop_browse_text settings to limit input to plain text or no custom text, and ensure that any remaining input is properly escaped before rendering in the page.

Generated by OpenCVE AI on June 6, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 06 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Glenwpcoder
Glenwpcoder drag And Drop Multiple File Upload For Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Glenwpcoder
Glenwpcoder drag And Drop Multiple File Upload For Contact Form 7
Wordpress
Wordpress wordpress

Sat, 06 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Description The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Glenwpcoder Drag And Drop Multiple File Upload For Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-06T11:44:26.256Z

Reserved: 2026-05-19T13:22:08.086Z

Link: CVE-2026-8991

cve-icon Vulnrichment

Updated: 2026-06-06T11:44:21.610Z

cve-icon NVD

Status : Received

Published: 2026-06-06T04:17:41.667

Modified: 2026-06-06T04:17:41.667

Link: CVE-2026-8991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T04:30:12Z

Weaknesses