CyberRota Analysis
AI-GeneratedThe Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress versions prior to 1.3.9.9 is vulnerable due to improper escaping of a setting used as an HTML tag name, enabling administrators to inject arbitrary web scripts. This flaw poses a significant risk as it allows for cross-site scripting (XSS) attacks on any front-end page that renders the upload field. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.