A security flaw has been found in the “Drag and Drop Multiple File Upload for Contact Form 7” plugin for WordPress. This vulnerability could allow unauthorized individuals to delete files that have been uploaded to your website. It primarily affects installations where the “Send attachments as links” setting is turned on. Additionally, an arbitrary file upload issue was also addressed, which could allow certain dangerous file types (.phar and .svg) to be uploaded when the plugin’s blacklist mode was active.
CVE Details
Product Name: Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress
Published Date: January 15, 2026
Severity: Low
Status: Analyzed
Affected Products
This vulnerability impacts all versions of the “Drag and Drop Multiple File Upload for Contact Form 7” plugin for WordPress up to, and including, version 1.3.9.2.
Current Status
The status of this vulnerability is “Analyzed,” meaning that its details have been investigated and confirmed.
Severity Level
The vulnerability is rated as Low severity. While it could lead to the deletion of uploaded files, which is a concern for data integrity and availability, it does not typically allow for complete website takeover or direct code execution that would result in high-impact damage. However, it’s still important to address this issue promptly to maintain the security and reliability of your website.
Possible Solutions
The developers have released a fix for this vulnerability. To secure your WordPress website, it is crucial to update the “Drag and Drop Multiple File Upload for Contact Form 7” plugin to version 1.3.9.3 or later. This update addresses the missing ownership check that allowed unauthorized file deletion and also fixes the arbitrary file upload issue.
Regularly updating all your WordPress plugins, themes, and core installation is a fundamental security practice. Always back up your website before performing any updates.
References
https://plugins.trac.wordpress.org/changeset/3428236/drag-and-drop-multiple-file-upload-contact-form-7
https://www.wordfence.com/threat-intel/vulnerabilities/id/1a182243-b24a-4c46-8b65-6b38d8509a51?source=cve


