CVE-2023-4821: Codedropz Drag And Drop Multiple File Uploader

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

Affected products

  • Codedropz Drag And Drop Multiple File Uploader: before 1.1.1 (fixed in 1.1.1)

Published 2023-10-16. Last modified 2026-06-17.