The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
We have discovered 18,162 live websites that are affected by CVE-2026-14325.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 18,162 live websites (100% of Drag And Drop Multiple File Upload Contact Form 7 install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 60 versions ( 100% of all versions) |
| 3,301 websites | |
| 3,676 websites | |
| 962 websites | |
| 891 websites | |
| 833 websites | |
| 756 websites | |
| 701 websites | |
| 664 websites | |
| 573 websites | |
| 454 websites |
| .com | 5,392 websites |
| .de | 2,817 websites |
| .ru | 616 websites |
| .co.uk | 568 websites |
| .nl | 541 websites |
| .org | 533 websites |
| .it | 508 websites |
| .pl | 501 websites |
| .fr | 478 websites |
| .com.au | 372 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********************.com | **,*** | ||
| ******.cc | **,*** | ||
| ********.me | **,*** | ||
| ****.hr | **,*** | ||
| ******.pt | **,*** | ||
| ****************.org | **,*** | ||
| *******.com | **,*** | ||
| ****.si | **,*** | ||
| *******.org | **,*** | ||
| **********************.**.uk | **,*** |
FAQ