
Cloud Vulnerability DB
A community-led vulnerabilities database
The drag-and-drop-multiple-file-upload-contact-form-7 WordPress plugin before version 1.3.3.3 contained an Unrestricted File Upload vulnerability (CVE-2020-12800). This vulnerability allowed attackers to perform remote code execution by manipulating the supported_type parameter to php% and uploading a .php% file. The vulnerability affected WordPress installations with both this plugin and Contact Form 7 installed (CVE Mitre, WPScan).
The vulnerability existed due to improper file upload validation in the dnd_codedropz_upload AJAX action. Attackers could bypass the security checks implemented in the plugin and upload malicious PHP files. The vulnerability was discovered and reported with a working proof of concept exploit (WPScan).
The vulnerability allowed attackers to achieve remote code execution on affected WordPress installations, potentially leading to complete server compromise. This could result in unauthorized access to sensitive data, website defacement, or the server being used for malicious purposes (WPScan).
The vulnerability was publicly disclosed with a working exploit, making it highly exploitable. The exploit code was publicly available on GitHub, and the vulnerability required no authentication to exploit. The only prerequisite was having both the vulnerable plugin and Contact Form 7 installed on the target system (WPScan).
The vulnerability was patched in version 1.3.3.3 of the plugin. Users were advised to update to this version immediately. The fix implemented proper file upload validation to prevent unauthorized file types from being uploaded (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."