Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-12800
WordPress vulnerability analysis and mitigation

Overview

The drag-and-drop-multiple-file-upload-contact-form-7 WordPress plugin before version 1.3.3.3 contained an Unrestricted File Upload vulnerability (CVE-2020-12800). This vulnerability allowed attackers to perform remote code execution by manipulating the supported_type parameter to php% and uploading a .php% file. The vulnerability affected WordPress installations with both this plugin and Contact Form 7 installed (CVE Mitre, WPScan).

Technical details

The vulnerability existed due to improper file upload validation in the dnd_codedropz_upload AJAX action. Attackers could bypass the security checks implemented in the plugin and upload malicious PHP files. The vulnerability was discovered and reported with a working proof of concept exploit (WPScan).

Impact

The vulnerability allowed attackers to achieve remote code execution on affected WordPress installations, potentially leading to complete server compromise. This could result in unauthorized access to sensitive data, website defacement, or the server being used for malicious purposes (WPScan).

Exploitability

The vulnerability was publicly disclosed with a working exploit, making it highly exploitable. The exploit code was publicly available on GitHub, and the vulnerability required no authentication to exploit. The only prerequisite was having both the vulnerable plugin and Contact Form 7 installed on the target system (WPScan).

Mitigation and workarounds

The vulnerability was patched in version 1.3.3.3 of the plugin. Users were advised to update to this version immediately. The fix implemented proper file upload validation to prevent unauthorized file types from being uploaded (WordPress Plugin).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management