CVE-2026-14325 PUBLISHED

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting

Assigner: WPScan
Reserved: 01.07.2026 Published: 21.08.2026 Updated: 21.08.2026

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.

Product Status

Vendor Unknown
Product Drag and Drop Multiple File Upload for Contact Form 7
Versions Default: unaffected
  • affected from 0 to 1.3.9.9 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE