Skip to content
Noroxi

codedropz records

15 published records for vendor codedropz.

All records

15 records
  • CVE-2020-12800
    63This week

    The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code ex

    CriticalCVSS 9.8WeaponizedEPSS 79%

    codedropz · drag and drop multiple file upload - contact form 7Jun 8, 2020

  • Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    codedropz · drag and drop multiple file upload - contact form 7Jun 17, 2025

  • Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    codedropz · drag and drop multiple file upload - contact form 7Mar 1, 2023

  • Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8No exploitEPSS 2%

    codedropz · drag and drop multiple file upload - contact form 7Nov 22, 2023

  • WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 1%

    codedropz · drag and drop multiple file upload for woocommerceDec 21, 2023

  • Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion

    CriticalCVSS 9.1No exploitEPSS 0%

    codedropz · drag and drop multiple file upload - contact form 7Jan 31, 2025

  • CVE-2025-2328
    35Monitor

    Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion

    HighCVSS 8.8No exploitEPSS 1%

    codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2025

  • CVE-2025-2485
    35Monitor

    Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion

    HighCVSS 8.8No exploitEPSS 1%

    codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2025

  • WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    codedropz · drag and drop multiple file upload - contact form 7May 24, 2023

  • CVE-2024-3717
    30Monitor

    Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure

    HighCVSS 7.5No exploitEPSS 1%

    codedropz · drag and drop multiple file upload - contact form 7May 2, 2024

  • Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion

    HighCVSS 7.4No exploitEPSS 0%

    codedropz · contact form 7Jan 15, 2026

  • CVE-2022-0595
    25Monitor

    Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS

    MediumCVSS 5.4Proof of conceptEPSS 14%

    codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2022

  • CVE-2023-1282
    24Monitor

    Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    codedropz · drag and drop multiple file upload - contact form 7Apr 17, 2023

  • CVE-2023-4821
    21Monitor

    Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    codedropz · drag and drop multiple file uploaderOct 16, 2023

  • CVE-2022-3282
    17Monitor

    Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass

    MediumCVSS 4.3No exploitEPSS 1%

    codedropz · drag and drop multiple file upload - contact form 7Oct 17, 2022