← Back

CVE-2025-14457

nvd nist
Published: Jan 15, 2026Modified: Jan 23, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.

Affected (1)

1 product
Contact Form 7
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.3.9.2

Timeline

No history available yet.