CVE-2026-14325
Received Received - Intake

Stored XSS in Drag and Drop Multiple File Upload for Contact Form 7 WordPress Plugin

Vulnerability report for CVE-2026-14325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: WPScan

Description

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder drag_and_drop_multiple_file_upload_for_contact_form_7 to 1.3.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before version 1.3.9.9. It occurs because the plugin does not escape a setting before using it as an HTML tag name in front-end output, allowing administrators to inject malicious scripts that execute on pages rendering the upload field.

Detection Guidance

Check the installed version of the Drag and Drop Multiple File Upload for Contact Form 7 plugin. If it is below 1.3.9.9, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

If you are an administrator using the vulnerable plugin, an attacker with administrator access could inject malicious scripts. These scripts could then execute on any front-end page that displays the upload field, potentially stealing user data, session cookies, or performing actions on behalf of users.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations could face compliance violations, legal penalties, or reputational damage if user data is compromised through this exploit.

Mitigation Strategies

Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to version 1.3.9.9 or later immediately. Remove or disable the plugin if updating is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart