CVE-2025-3515 Details
Description
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly validated before being passed to the PHP interpreter.
A vulnerability exists in the WordPress plugin 'Drag and Drop Multiple File Upload for Contact Form 7' in versions through 1.3.8.9. The issue arises from inadequate validation of file types, allowing unauthenticated attackers to upload potentially harmful files, such as .phar files, to the server. This could lead to remote code execution on servers that process .phar files as executable PHP, especially in default Apache with mod_php, where file extensions are not rigorously checked before being executed by the PHP interpreter.
Users are advised to update the 'Drag and Drop Multiple File Upload for Contact Form 7' plugin to version 1.3.9.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| codedropz drag and drop multiple file upload - contact form 7 | < 1.3.9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | Initial Analysis | [email protected] |
| Jun 17, 2025 | New CVE Received | [email protected] |