Codedropz develops a focused portfolio of WordPress file-upload plugins, primarily centered on drag-and-drop uploaders for Contact Form 7 and WooCommerce integration, that handle user-supplied file submissions across many WordPress-based websites. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, clustering around upload-handling and access-control weaknesses—unrestricted file uploads, path traversal, authorization bypass, CSRF, and unsafe deserialization—that are endemic to web-accessible form processors. Defenders should prioritize this vendor's plugin updates, especially for internet-facing contact and commerce forms, since these attack surfaces are routinely scanned and weaponized; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codedropz over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12800CRITICAL The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php | Jun 8, 2020 | 9.8 | 82 | NO | YES |
CVE-2025-3515CRITICAL The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up t | Jun 17, 2025 | 9.8 | 42 | NO | YES |
CVE-2023-5822CRITICAL The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7 | Nov 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-1112CRITICAL A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file | Mar 1, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-0595MEDIUM The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stor | Mar 28, 2022 | 5.4 | 29 | NO | YES |
CVE-2025-14457HIGH The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedr | Jan 15, 2026 | 7.4 | 27 | NO | NO |
CVE-2022-45377CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple Fi | Dec 21, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-45364HIGH Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | May 24, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-2328HIGH The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_ | Mar 28, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-2485HIGH The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserializati | Mar 28, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codedropz.
Media articles that mention a CVE ID that affects a product developed by Codedropz — matched by CVE ID, not by vendor name.