{"id":19019233,"date":"2026-09-14T07:06:09","date_gmt":"2026-09-14T07:06:09","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19019233"},"modified":"2026-09-14T07:58:03","modified_gmt":"2026-09-14T07:58:03","slug":"vulnerability-detected-10","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/vulnerability-detected-10\/","title":{"rendered":"Vulnerability detected"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Our Plesk server reported a vulnerability<br \/><br \/>drag-and-drop-multiple-file-upload-contact-form-7 version 1.4.0 has vulnerability(s):<br \/><strong>CVE-2025-5746<\/strong><br \/><br \/>As a quick google search explains:<br \/><br \/>The vulnerability stems from missing file type validation inside the plugin&#8217;s chunk upload handling function (<code>dnd_upload_cf7_upload_chunks()<\/code>). Because the plugin fails to properly check and verify the type of uploaded content before saving it to the server, unauthenticated attackers can upload malicious files (such as PHP scripts or webshells)<\/p>\n","protected":false},"template":"","class_list":["post-19019233","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19019233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19019233\/revisions"}],"predecessor-version":[{"id":19019282,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19019233\/revisions\/19019282"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19019233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}