CVE-2020-12800 is a critical unrestricted file upload vulnerability affecting the codedropz drag_and_drop_multiple_file_upload_-_contact_form_7 plugin for WordPress versions prior to 1.3.3.3. This flaw allows unauthenticated attackers to achieve remote code execution by manipulating file types during upload. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk due to its low attack complexity and complete compromise potential. While not currently listed in CISA's KEV catalog, public exploit modules are available in Metasploit and Nuclei, though there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.3.3CPE matchmatch criteria | cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_-_contact_form_7:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.