The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codedropz
Codedropz drag And Drop Multiple File Upload - Contact Form 7 Wordpress Wordpress wordpress |
|
| Vendors & Products |
Codedropz
Codedropz drag And Drop Multiple File Upload - Contact Form 7 Wordpress Wordpress wordpress |
Thu, 15 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled. | |
| Title | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-15T06:45:04.078Z
Updated: 2026-01-15T14:47:51.069Z
Reserved: 2025-12-10T14:55:41.035Z
Link: CVE-2025-14457
Updated: 2026-01-15T14:47:42.600Z
Status : Awaiting Analysis
Published: 2026-01-15T07:16:02.717
Modified: 2026-01-16T15:55:33.063
Link: CVE-2025-14457
No data.