VYPR

Drag And Drop Multiple File Upload For Woocommerce

by WordPress

Source repositories

CVEs (6)

  • CVE-2025-49885CriJun 27, 2025
    risk 0.65cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-upload-wc-pro allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce:…

  • CVE-2025-2941CriApr 5, 2025
    risk 0.64cvss 9.8epss 0.02

    The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated…

  • CVE-2026-16054CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload…

  • CVE-2025-4403CriMay 9, 2025
    risk 0.57cvss 9.8epss 0.02

    The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or…

  • CVE-2022-45377MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.

  • CVE-2023-4821MedOct 16, 2023
    risk 0.35cvss 5.4epss 0.00

    The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.