Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codedropz

First CVE: Jun 8, 2020Active for: 6 yearsTotal CVEs: 15
60.0
VTI Score
TOP TARGET

Codedropz develops a focused portfolio of WordPress file-upload plugins, primarily centered on drag-and-drop uploaders for Contact Form 7 and WooCommerce integration, that handle user-supplied file submissions across many WordPress-based websites. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, clustering around upload-handling and access-control weaknesses—unrestricted file uploads, path traversal, authorization bypass, CSRF, and unsafe deserialization—that are endemic to web-accessible form processors. Defenders should prioritize this vendor's plugin updates, especially for internet-facing contact and commerce forms, since these attack surfaces are routinely scanned and weaponized; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codedropz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2020
6 years ago
Most Recent CVE
Jan 15, 2026
190 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-12800CRITICAL
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php
Jun 8, 20209.882NOYES
CVE-2025-3515CRITICAL
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up t
Jun 17, 20259.842NOYES
CVE-2023-5822CRITICAL
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7
Nov 22, 20239.831NONO
CVE-2023-1112CRITICAL
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file
Mar 1, 20239.831NONO
CVE-2022-0595MEDIUM
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stor
Mar 28, 20225.429NOYES
CVE-2025-14457HIGH
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedr
Jan 15, 20267.427NONO
CVE-2022-45377CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple Fi
Dec 21, 20239.826NONO
CVE-2022-45364HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
May 24, 20238.826NONO
CVE-2025-2328HIGH
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_
Mar 28, 20258.825NONO
CVE-2025-2485HIGH
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserializati
Mar 28, 20258.824NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
27%
33%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None9 (60.0%)
Unknown0 (0.0%)
Required6 (40.0%)
Privileges Required
Low3 (20.0%)
High0 (0.0%)
None12 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
3 CVEs
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codedropz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codedropz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codedropz's Products

View all 5 CNAs →

Top CWEs