๐Ÿ” CVE Alert

CVE-2026-14325

UNKNOWN 0.0

Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.

Vendor unknown
Product drag and drop multiple file upload for contact form 7
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown drag and drop multiple file upload for contact form 7

Be the first to know when new unknown vulnerabilities affecting unknown drag and drop multiple file upload for contact form 7 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Drag and Drop Multiple File Upload for Contact Form 7
0 < 1.3.9.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fc723849-62d3-4c87-a0ad-5e5354961303/

Credits

Sai Praneeth Koti WPScan