CVE-2025-14457: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dndcodedropzuploaddelete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14457?
The severity of CVE-2025-14457 is considered high due to the potential for unauthorized file deletion.
How do I fix CVE-2025-14457?
To fix CVE-2025-14457, update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to version 1.3.9.3 or higher.
Who is affected by CVE-2025-14457?
CVE-2025-14457 affects users of the Drag and Drop Multiple File Upload for Contact Form 7 plugin up to version 1.3.9.2.
What is the impact of CVE-2025-14457?
The impact of CVE-2025-14457 includes the risk of unauthorized users being able to delete files without proper authorization.
Is CVE-2025-14457 actively exploited?
There is currently no public information confirming active exploitation of CVE-2025-14457, but it poses a significant risk to affected systems.