CVE-2025-2328
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 28, 2025
CWE ID 22
Summary
CVE-2025-2328 is a vulnerability affecting the Drag and Drop Multiple File Upload feature of Contact Form 7 plugin for WordPress. In all versions up to and including 1.3.8.7, insufficient file path validation in the 'dnd_remove_uploaded_files' function allows unauthenticated attackers to add arbitrary file paths to uploaded files. This can result in remote code execution, particularly when an administrator deletes a message. The Flamingo plugin must be installed and activated for successful exploitation of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.