CVE-2024-3717CVSS 5.3CMS
CVE-2024-3717: drag and drop multiple file upload - contact form 7 vulnerability
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.
- CVSS
- 5.3 MEDIUM
- EPSS
- 47.42%
- Known exploited
- not in KEV
- Product
- drag and drop multiple file upload - contact form 7
What is known
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.