Vulnerability Description
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14325?
CVE-2026-14325 is a vulnerability with a CVSS score of 3.5 (LOW). The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users wi...
How severe is CVE-2026-14325?
CVE-2026-14325 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14325?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.