Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure
Strategic Overview
- Status
- Patched in 1.3.7.8
- Affected Plugin
- Drag and Drop Multiple File Upload for Contact Form 7
- Affected Version
<= 1.3.7.7- CVSS
- 5.3Medium
- Weakness type
- CWE-922 · Insecure Storage of Sensitive Information
- CVE
CVE-2024-3717
At a glance
CVE-2024-3717 is a medium-severity Insecure Storage of Sensitive Information vulnerability in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin, affecting versions <= 1.3.7.7. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 1.3.7.8; sites on affected versions should update now. Disclosed April 2024, reported by Tim Coen.
Vulnerability Overview
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-922: Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Remediation
Update to version 1.3.7.8, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Drag and Drop Multiple File Upload for Contact Form 7 1.3.7.8 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Drag and Drop Multiple File Upload for Contact Form 7
- 9.8CVE-2026-18781: Drag and Drop Multiple File Upload… RCE
CVE-2026-18781 - 9.8CVE-2020-12800: Drag and Drop Multiple… Arbitrary File Upload
CVE-2020-12800 - 8.8CVE-2025-2328: Drag and Drop Multiple… Arbitrary File Deletion
CVE-2025-2328 - 8.8CVE-2022-45364: Drag and Drop Multiple… CSRF in dnd_upload_cf7_upload
CVE-2022-45364 - 8.1CVE-2026-5718: Drag and Drop Multiple… Arbitrary File Upload
CVE-2026-5718 - 8.1CVE-2026-3459: Drag and Drop Multiple… Arbitrary File Upload
CVE-2026-3459 - 8.1CVE-2025-3515: Drag and Drop Multiple… Arbitrary File Upload
CVE-2025-3515 - 8.1CVE-2023-5822: Drag and Drop Multiple… Arbitrary File Upload
CVE-2023-5822
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C