The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
We have discovered 13,214 live websites that are affected by CVE-2025-14457.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 13,214 live websites (73% of Drag And Drop Multiple File Upload Contact Form 7 install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 55 versions ( 95% of all versions) |
| 2,294 websites | |
| 2,653 websites | |
| 719 websites | |
| 660 websites | |
| 594 websites | |
| 583 websites | |
| 557 websites | |
| 527 websites | |
| 377 websites | |
| 312 websites |
| .com | 3,815 websites |
| .de | 2,022 websites |
| .ru | 580 websites |
| .co.uk | 441 websites |
| .it | 408 websites |
| .pl | 373 websites |
| .nl | 356 websites |
| .fr | 327 websites |
| .org | 324 websites |
| .com.au | 239 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********************.com | **,*** | ||
| ****.hr | **,*** | ||
| ******.pt | **,*** | ||
| *******.org | **,*** | ||
| **********************.**.uk | **,*** | ||
| **********.ro | **,*** | ||
| **.***.pl | **,*** | ||
| **************.com | **,*** | ||
| ***********.**.jp | **,*** | ||
| ****************.com | **,*** |
FAQ