CVE-2020-12800: Codedropz Drag And Drop Multiple File Upload - Contact Form 7
Critical severity, CVSS 9.8. EPSS: 78.6% chance of exploitation in the next 30 days.
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
Affected products
- Codedropz Drag And Drop Multiple File Upload - Contact Form 7: before 1.3.3.3 (fixed in 1.3.3.3)
Published 2020-06-08. Last modified 2026-06-17.