Medium severity5.3NVD Advisory· Published Jan 31, 2025· Updated Jun 17, 2026
CVE-2024-12267
CVE-2024-12267
Description
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_-_contact_form_7:*:*:*:*:*:wordpress:*:*Range: <1.3.8.6
- Range: <=1.3.8.5
- glenwpcoder/Drag and Drop Multiple File Upload for Contact Form 7v5Range: 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.