CVE-2025-8464
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-16

Last updated on: 2025-08-18

Assigner: Wordfence

Description
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directory. The impact of this vulnerability is limited, as file types are validated and only safe ones can be uploaded, while deletion is limited to the plugin's uploads folder.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-16
Last Modified
2025-08-18
Generated
2026-05-07
AI Q&A
2025-08-16
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wordpress drag_and_drop_multiple_file_upload_for_contact_form_7 1.3.9.0
wordpress drag_and_drop_multiple_file_upload_for_contact_form_7 1.3.9.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Directory Traversal issue in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin (versions up to 1.3.9.0). It allows unauthenticated attackers to upload and delete files outside the intended directory by exploiting the wpcf7_guest_user_id cookie.


How can this vulnerability impact me? :

The impact is limited because only safe file types can be uploaded and deletion is restricted to the plugin's uploads folder. However, attackers can still upload and delete files outside the intended directory, potentially leading to unauthorized modification of files within the plugin's scope.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart