The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.
History

Tue, 18 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Fri, 31 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 11:15:00 +0000

Type Values Removed Values Added
Description The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.
Title Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-18T18:42:37.166Z

Reserved: 2024-12-05T17:24:03.437Z

Link: CVE-2024-12267

cve-icon Vulnrichment

Updated: 2025-01-31T15:22:07.279Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-31T11:15:09.473

Modified: 2025-02-18T19:15:12.083

Link: CVE-2024-12267

cve-icon Redhat

No data.