Drag and Drop Multiple File Upload for Contact Form 7 Unauthorized Data Modification Vulnerability (CVE-2025-14457) — Low Severity

A security flaw has been found in the “Drag and Drop Multiple File Upload for Contact Form 7” plugin for WordPress. This vulnerability could allow unauthorized individuals to delete files that have been uploaded to your website. It primarily affects installations where the “Send attachments as links” setting is turned on. Additionally, an arbitrary file upload issue was also addressed, which could allow certain dangerous file types (.phar and .svg) to be uploaded when the plugin’s blacklist mode was active.

CVE Details

Product Name: Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress

Published Date: January 15, 2026

Severity: Low

Status: Analyzed

Affected Products

This vulnerability impacts all versions of the “Drag and Drop Multiple File Upload for Contact Form 7” plugin for WordPress up to, and including, version 1.3.9.2.

Current Status

The status of this vulnerability is “Analyzed,” meaning that its details have been investigated and confirmed.

Severity Level

The vulnerability is rated as Low severity. While it could lead to the deletion of uploaded files, which is a concern for data integrity and availability, it does not typically allow for complete website takeover or direct code execution that would result in high-impact damage. However, it’s still important to address this issue promptly to maintain the security and reliability of your website.

Possible Solutions

The developers have released a fix for this vulnerability. To secure your WordPress website, it is crucial to update the “Drag and Drop Multiple File Upload for Contact Form 7” plugin to version 1.3.9.3 or later. This update addresses the missing ownership check that allowed unauthorized file deletion and also fixes the arbitrary file upload issue.

Regularly updating all your WordPress plugins, themes, and core installation is a fundamental security practice. Always back up your website before performing any updates.

References

https://plugins.trac.wordpress.org/changeset/3428236/drag-and-drop-multiple-file-upload-contact-form-7

https://www.wordfence.com/threat-intel/vulnerabilities/id/1a182243-b24a-4c46-8b65-6b38d8509a51?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.