• Resolved Autosoft B.V.

    (@autosoftbv)


    Our Plesk server reported a vulnerability

    drag-and-drop-multiple-file-upload-contact-form-7 version 1.4.0 has vulnerability(s):
    CVE-2025-5746

    As a quick google search explains:

    The vulnerability stems from missing file type validation inside the plugin’s chunk upload handling function (dnd_upload_cf7_upload_chunks()). Because the plugin fails to properly check and verify the type of uploaded content before saving it to the server, unauthenticated attackers can upload malicious files (such as PHP scripts or webshells)

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Glen Don Mongaya

    (@glenwpcoder)

    Hello @autosoftbv ,

    Thanks for reaching out.

    “drag-and-drop-multiple-file-upload-contact-form-7 version 1.4.0 has vulnerability(s):
    CVE-2025-5746” – Our free version plugin doesn’t have reported issue similar to this and it doesn’t have the function name “dnd_upload_cf7_upload_chunks” or if you can provide the details that would be great.

    “CVE-2025-5746” The reported issue seems related to our other plugin “Drag & Drop file upload – WooCommerce Pro V1.7.1” not this CF7 plugin, we’ve already released a new version last year that added file type validation in version V1.7.2 make sure you are using the updated version.

    Change log for v1.7.2 can be found here – https://www.codedropz.com/changelog-wc/
    Code added : https://snipboard.io/xr8k2d.jpg
    WordFence Patched: https://www.wordfence.com/threat-intel/vendor/vulnerability-report/3c1f625e-4456-45e4-8a7f-809b22edb66b

    The function “dnd_upload_cf7_upload_chunks” is misleading and was changed to “dndmfu_wc_upload_chunks“.

    Please let me know if you have any other concern.

    Glen

    • This reply was modified 2 weeks, 3 days ago by Glen Don Mongaya.
    • This reply was modified 2 weeks, 3 days ago by Yui.
    Thread Starter Autosoft B.V.

    (@autosoftbv)

    Thank you for explaining.
    Perhaps the Google search result was misleading / incorrect. sorry about that.

    The notification we got, was send by Imunify AV (a mallware scanner within Plesk)
    and i cant find any information about the vulnerability anymore, so perhaps it was an outdated notice or false/positive because of your other plugin.

    The native wordpress toolkit within Plesk itself doesn’t have any Vulnerability notices concerning your plugin, so I assume it’s not an issue.

    Sorry for bothering, better safe than sorry, thanks for the reply.

    If i do find any notices, i wil let you know.
    Topic can be closed.

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.