CVE-2020-12800 — WordPress
CVE-2020-12800 is a Unrestricted File Upload vulnerability. 5 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php%…
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
Affected Products
drag and drop multiple file upload - contact form 7codedropzResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.…
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.…
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.…
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.…
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2020-12800 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Treat uploaded files as untrusted until proven otherwise: validate the actual content type rather than the supplied extension, store uploads outside the web root on a volume mounted without execute permission, and rename them to server-generated identifiers so an attacker cannot choose the path a request will later resolve.
How to detect CVE-2020-12800
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2020-12800 -u https://target- Template
- WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution
- Severity
- critical
- Impact
- Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected WordPress site.
- Remediation
- Update the Contact Form 7 plugin to version 1.3.3.3 or later to mitigate this vulnerability.
Template by ProjectDiscovery nuclei-templates (dwisiswant0), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is CVE-2020-12800 in your dependencies?
Find it across , including transitive dependencies.