CVE-2024-3717: Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wpdndcf7uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3717?
CVE-2024-3717 has a high severity rating due to the potential for sensitive information exposure.
How do I fix CVE-2024-3717?
To fix CVE-2024-3717, update the Drag and Drop Multiple File Upload – Contact Form 7 plugin to version 1.3.7.8 or later.
Who is affected by CVE-2024-3717?
CVE-2024-3717 affects all versions of the Drag and Drop Multiple File Upload – Contact Form 7 plugin up to and including version 1.3.7.7.
Can unauthenticated attackers exploit CVE-2024-3717?
Yes, unauthenticated attackers can exploit CVE-2024-3717 to access sensitive information.
What directory is associated with CVE-2024-3717?
CVE-2024-3717 is associated with the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory.