SecAlerts
codedropz logo

codedropz

Security Risk Profile

63
/100
high

Security Risk Score

Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 8, 2020 to present

15
Total CVEs
11
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
63/100
high

Severity Distribution

Critical
6
High
5
Medium
4
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Malicious File Upload
4
2
XSS
3
3
Path Traversal
2
4
CSRF
1

Most Affected Products

1. codedropz Drag And Drop Multiple File Upload - Contact Form 7 Wordpress13
2. WordPress Drag and Drop Multiple File Upload – Contact Form 72
3. wordpress/drag-and-drop-multiple-file-upload-for-contact-form-71
4. codedropz Contact Form 7 Wordpress1
5. WordPress Drag and Drop Multiple File Upload for Contact Form 71

Recent Vulnerabilities

See more →
CVE-2025-14457
CVSS 7.4high

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion

1/15/2026
CVE-2025-3515
CVSS 9.8critical

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks

6/17/2025
CVE-2025-2485
CVSS 8.8high

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion

3/28/2025
CVE-2025-2328
CVSS 8.8high

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion

3/28/2025
CVE-2024-12267
CVSS 9.1critical

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion

1/31/2025
CVE-2024-3717
CVSS 7.5EPSS 0%high

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure

5/2/2024
CVE-2022-45377
CVSS 9.8critical

WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities

12/21/2023
CVE-2023-5822
CVSS 9.8EPSS 0%critical

Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload

11/22/2023
CVE-2023-4821
CVSS 5.4medium

Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting

10/16/2023🔧 No Patch
CVE-2022-45364
CVSS 8.8high

WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)

5/24/2023

Monitor codedropz in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.