Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drag And Drop Multiple File Uploader Pro - Contact Form 7 Project
Drag And Drop Multiple File Uploader Pro - Contact Form 7 Project drag And Drop Multiple File Uploader Pro - Contact Form 7 Wordpress Wordpress wordpress |
|
| Vendors & Products |
Drag And Drop Multiple File Uploader Pro - Contact Form 7 Project
Drag And Drop Multiple File Uploader Pro - Contact Form 7 Project drag And Drop Multiple File Uploader Pro - Contact Form 7 Wordpress Wordpress wordpress |
|
| Metrics |
cvssV3_1
|
Fri, 21 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Fri, 21 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Title | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T12:50:36.249Z
Reserved: 2026-07-01T12:15:58.717Z
Link: CVE-2026-14325
Updated: 2026-08-21T12:50:26.695Z
Status : Received
Published: 2026-08-21T07:16:24.430
Modified: 2026-08-21T13:16:51.633
Link: CVE-2026-14325
No data.
OpenCVE Enrichment
Updated: 2026-08-21T15:30:05Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')