CVE-2026-14325
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
| Vendor | unknown |
| Product | drag and drop multiple file upload for contact form 7 |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown drag and drop multiple file upload for contact form 7
Be the first to know when new unknown vulnerabilities affecting unknown drag and drop multiple file upload for contact form 7 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Drag and Drop Multiple File Upload for Contact Form 7
0 < 1.3.9.9
References
Credits
Sai Praneeth Koti WPScan