Executive brief
The Drag and Drop Multiple File Upload plugin for WordPress, which adds advanced file upload capabilities to Contact Form 7, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious sites, or deface the website. This vulnerability can be exploited by remote attackers without needing any login credentials.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (such as an administrator) to perform an action, like clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or delivery of further malware. The issue is fixed in version 1.3.9.8.
Affected products
- CodePeople Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7
Timeline
- 2026-04-22: other: Reported by researcher fayespiegel
- 2026-06-03: disclosed: Initial disclosure by Patchstack
- 2026-06-03: patched: Version 1.3.9.8 released to address the vulnerability
- 2026-06-15: advisory: NVD published CVE-2026-49055