SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14325

LOW · CVSS 3.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress versions prior to 1.3.9.9 is vulnerable due to improper escaping of a setting used as an HTML tag name, enabling administrators to inject arbitrary web scripts. This flaw poses a significant risk as it allows for cross-site scripting (XSS) attacks on any front-end page that renders the upload field. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-14325
Severity
LOW
CVSS
3.5
EPSS
0.14%
WordPress

Original NVD Description

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.