CVE-2025-14457

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.


We have discovered 13,214 live websites that are affected by CVE-2025-14457.

Run a Free Instant Scan




Affected Software

Product  Drag And Drop Multiple File Upload Contact Form 7
Category Wordpress Plugins
Vulnerable Domains13,214 live websites (73% of Drag And Drop Multiple File Upload Contact Form 7 install base)
Vulnerable Versions
  • from 0 through 1.3.9.2
Vulnerable Versions Count55 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 15, 2026
  • Updated - Jan 15, 2026

Credits

  • Angus Girvan (finder)

Website Distribution by Country

Number of websites using CVE-2025-14457
United States2,294 websites



Germany2,653 websites
Russia719 websites
France660 websites
GB594 websites
Japan583 websites
Italy557 websites
Poland527 websites
Netherlands377 websites
Spain312 websites

Website Distribution by TLD

Number of websites using CVE-2025-14457
.com3,815 websites
.de2,022 websites
.ru580 websites
.co.uk441 websites
.it408 websites
.pl373 websites
.nl356 websites
.fr327 websites
.org324 websites
.com.au239 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14457

Top websites that are affected by CVE-2025-14457. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********************.com United States**,***
****.hr Croatia**,***
******.pt Portugal**,***
*******.org France**,***
**********************.**.uk GB**,***
**********.ro Romania**,***
**.***.pl Poland**,***
**************.com United States**,***
***********.**.jp Japan**,***
****************.com United States**,***
See full domain list

FAQ

CVE-2025-14457 is Missing Authorization in Drag And Drop Multiple File Upload Contact Form 7
A total of 13,214 websites have been identified as vulnerable to CVE-2025-14457, based on global website indexing conducted by WebTechSurvey.
The Drag And Drop Multiple File Upload Contact Form 7 is affected by the CVE-2025-14457 vulnerability.
Drag And Drop Multiple File Upload Contact Form 7 versions up to and including 1.3.9.2 are vulnerable to CVE-2025-14457.