CVE-2025-2328 | Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin Path Validation dnd_remove_uploaded_files unrestricted upload
A vulnerability, which was classified as critical, has been found in Contact Form Drag and Drop Multiple File Upload for Contact Form 7 Plugin up to 1.3.8.7 on WordPress. This issue affects the function dnd_remove_uploaded_files of the component Path Validation Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2328. The attack may be initiated remotely. There is no exploit available.