Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2025-2328 First vendor Publication 2025-03-28
Vendor Cve Last vendor Modification 2025-03-28

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Overall CVSS Score 8.8
Base Score 8.8 Environmental Score 8.8
impact SubScore 5.9 Temporal Score 8.8
Exploitabality Sub Score 2.8
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction Required
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated attackers to add arbitrary file paths (such as ../../../../wp-config.php) to uploaded files on the server, which can easily lead to remote code execution when an Administrator deletes the message. Exploiting this vulnerability requires the Flamingo plugin to be installed and activated.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2328

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25)

Sources (Detail)

https://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload...
https://plugins.trac.wordpress.org/changeset/3261964/
https://www.wordfence.com/threat-intel/vulnerabilities/id/0f6cca7a-b8ff-4ca5-...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
Date Informations
2025-05-01 14:23:18
  • Multiple Updates
2025-05-01 14:23:04
  • Multiple Updates
2025-05-01 05:03:10
  • Multiple Updates
2025-05-01 05:02:59
  • Multiple Updates
2025-04-30 14:22:47
  • Multiple Updates
2025-04-30 14:22:35
  • Multiple Updates
2025-04-30 05:06:55
  • Multiple Updates
2025-04-30 05:06:44
  • Multiple Updates
2025-04-29 14:28:09
  • Multiple Updates
2025-04-29 14:27:58
  • Multiple Updates
2025-04-29 05:18:36
  • Multiple Updates
2025-04-29 05:18:24
  • Multiple Updates
2025-04-28 14:26:55
  • Multiple Updates
2025-04-28 14:26:44
  • Multiple Updates
2025-04-28 05:23:55
  • Multiple Updates
2025-04-28 05:23:41
  • Multiple Updates
2025-04-27 14:18:10
  • Multiple Updates
2025-04-27 14:18:00
  • Multiple Updates
2025-04-27 06:15:45
  • Multiple Updates
2025-04-27 06:15:34
  • Multiple Updates
2025-04-26 14:15:26
  • Multiple Updates
2025-04-26 14:15:15
  • Multiple Updates
2025-04-26 06:48:31
  • Multiple Updates
2025-04-26 06:48:19
  • Multiple Updates
2025-04-25 14:17:05
  • Multiple Updates
2025-04-25 14:16:54
  • Multiple Updates
2025-04-25 05:20:28
  • Multiple Updates
2025-04-25 05:20:15
  • Multiple Updates
2025-04-24 14:25:02
  • Multiple Updates
2025-04-24 14:24:51
  • Multiple Updates
2025-04-24 05:46:41
  • Multiple Updates
2025-04-24 05:46:29
  • Multiple Updates
2025-04-23 14:17:21
  • Multiple Updates
2025-04-23 14:17:10
  • Multiple Updates
2025-04-23 06:05:10
  • Multiple Updates
2025-04-23 06:04:59
  • Multiple Updates
2025-04-22 14:17:19
  • Multiple Updates
2025-04-22 14:17:08
  • Multiple Updates
2025-04-22 06:49:55
  • Multiple Updates
2025-04-22 06:49:43
  • Multiple Updates
2025-04-21 14:16:50
  • Multiple Updates
2025-04-21 14:16:40
  • Multiple Updates
2025-04-21 05:53:05
  • Multiple Updates
2025-04-21 05:52:44
  • Multiple Updates
2025-04-20 14:17:25
  • Multiple Updates
2025-04-20 14:17:14
  • Multiple Updates
2025-04-20 07:31:07
  • Multiple Updates
2025-04-20 07:30:52
  • Multiple Updates
2025-04-19 14:17:41
  • Multiple Updates
2025-04-19 14:17:29
  • Multiple Updates
2025-04-19 06:17:29
  • Multiple Updates
2025-04-19 06:17:18
  • Multiple Updates
2025-04-18 16:36:05
  • Multiple Updates
2025-04-18 16:35:54
  • Multiple Updates
2025-04-18 03:17:53
  • Multiple Updates
2025-04-18 03:17:40
  • Multiple Updates
2025-04-17 14:17:17
  • Multiple Updates
2025-04-17 14:17:05
  • Multiple Updates
2025-04-17 06:47:43
  • Multiple Updates
2025-04-17 06:47:29
  • Multiple Updates
2025-04-16 14:22:56
  • Multiple Updates
2025-04-16 14:22:45
  • Multiple Updates
2025-04-16 07:05:37
  • Multiple Updates
2025-04-16 07:05:26
  • Multiple Updates
2025-04-15 14:18:47
  • Multiple Updates
2025-04-15 14:18:36
  • Multiple Updates
2025-04-15 05:10:11
  • Multiple Updates
2025-04-15 05:10:00
  • Multiple Updates
2025-04-14 15:57:27
  • Multiple Updates
2025-04-14 15:57:16
  • Multiple Updates
2025-04-14 04:56:50
  • Multiple Updates
2025-04-14 04:56:11
  • Multiple Updates
2025-04-13 15:25:09
  • Multiple Updates
2025-04-13 15:24:58
  • Multiple Updates
2025-04-13 03:26:21
  • Multiple Updates
2025-04-13 03:26:09
  • Multiple Updates
2025-04-12 14:17:24
  • Multiple Updates
2025-04-12 14:17:13
  • Multiple Updates
2025-04-12 04:33:22
  • Multiple Updates
2025-04-12 04:33:01
  • Multiple Updates
2025-04-11 14:45:02
  • Multiple Updates
2025-04-11 14:44:51
  • Multiple Updates
2025-04-11 03:25:15
  • Multiple Updates
2025-04-11 03:25:04
  • Multiple Updates
2025-04-10 14:19:48
  • Multiple Updates
2025-04-10 14:19:37
  • Multiple Updates
2025-04-10 03:35:24
  • Multiple Updates
2025-04-10 03:35:12
  • Multiple Updates
2025-04-09 14:19:34
  • Multiple Updates
2025-04-09 14:19:23
  • Multiple Updates
2025-04-09 03:20:45
  • Multiple Updates
2025-04-09 03:20:34
  • Multiple Updates
2025-04-08 14:16:11
  • Multiple Updates
2025-04-08 14:16:00
  • Multiple Updates
2025-04-08 03:22:07
  • Multiple Updates
2025-04-08 03:21:56
  • Multiple Updates
2025-04-07 14:15:29
  • Multiple Updates
2025-04-07 14:15:18
  • Multiple Updates
2025-04-07 03:16:16
  • Multiple Updates
2025-04-07 03:16:05
  • Multiple Updates
2025-04-06 14:15:20
  • Multiple Updates
2025-04-06 14:15:09
  • Multiple Updates
2025-04-06 03:17:39
  • Multiple Updates
2025-04-06 03:17:27
  • Multiple Updates
2025-04-05 14:18:49
  • Multiple Updates
2025-04-05 14:18:38
  • Multiple Updates
2025-04-05 03:22:34
  • Multiple Updates
2025-04-05 03:22:23
  • Multiple Updates
2025-04-04 14:16:56
  • Multiple Updates
2025-04-04 14:16:45
  • Multiple Updates
2025-04-04 03:15:49
  • Multiple Updates
2025-04-04 03:15:37
  • Multiple Updates
2025-04-03 15:09:51
  • Multiple Updates
2025-04-03 15:09:35
  • Multiple Updates
2025-04-03 03:14:51
  • Multiple Updates
2025-04-03 03:14:41
  • Multiple Updates
2025-04-02 14:15:32
  • Multiple Updates
2025-04-02 14:15:21
  • Multiple Updates
2025-04-02 03:15:43
  • Multiple Updates
2025-04-02 03:15:32
  • Multiple Updates
2025-04-01 14:15:21
  • Multiple Updates
2025-04-01 14:15:10
  • Multiple Updates
2025-03-31 17:20:33
  • Multiple Updates
2025-03-28 17:20:42
  • First insertion