CVE-2025-2328

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 22

Summary

CVE-2025-2328 is a vulnerability affecting the Drag and Drop Multiple File Upload feature of Contact Form 7 plugin for WordPress. In all versions up to and including 1.3.8.7, insufficient file path validation in the 'dnd_remove_uploaded_files' function allows unauthenticated attackers to add arbitrary file paths to uploaded files. This can result in remote code execution, particularly when an administrator deletes a message. The Flamingo plugin must be installed and activated for successful exploitation of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share