Critical severity9.8NVD Advisory· Published Jun 8, 2020· Updated Jun 17, 2026
CVE-2020-12800
CVE-2020-12800
Description
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_-_contact_form_7:*:*:*:*:*:wordpress:*:*Range: <1.3.3.3
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/157951/WordPress-Drag-And-Drop-Multi-File-Uploader-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- wordpress.org/plugins/drag-and-drop-multiple-file-upload-contact-form-7/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.