CVE-2025-2485 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin dnd_upload_cf7_upload deserialization
A vulnerability has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress and classified as critical. Affected by this vulnerability is the function dnd_upload_cf7_upload. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-2485. The attack can be launched remotely. There is no exploit available.