CVE-2024-12267
Path Traversal in Codedropz Drag And Drop Multiple File Upload - Contact Form 7 ≤ 1.3.8.6
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NSummary
CVE-2024-12267 is a medium-severity External Control of File Name or Path (CWE-73) vulnerability in Codedropz Drag And Drop Multiple File Upload - Contact Form 7. Its CVSS base score is 5.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 25th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2024-12267 affects the Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.3.8.5. The vulnerability stems from insufficient file path validation in the dnd_codedropz_upload_delete() function, enabling limited arbitrary file deletion. It carries a CVSS v3.1 base score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) and is associated with CWE-73 (External Control of File Name or Path).
Unauthenticated attackers can exploit this issue remotely with low complexity and no privileges required. Successful exploitation allows deletion of limited arbitrary files on the server, though critical files such as wp-config.php cannot be targeted, preventing escalation to remote code execution.
Advisories reference a patch in the plugin's Trac changeset 3231973, which updates the dnd-upload-cf7.php file to address the validation flaw. Wordfence threat intelligence provides further details on the vulnerability at their dedicated page.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-50731
Vulnerability Data
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This…
more
makes it possible for unauthenticated attackers to delete limited arbitrary files on the server. It is not possible to delete files like wp-config.php that would make RCE possible.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V5.3.2
Mitigating Controls (NIST 800-53 r5) AI
Input validation directly rejects or sanitizes untrusted path strings before they reach filesystem operations.
Enforces authorization checks on the actual resource accessed, blocking unauthorized files even when a malicious path is supplied.
Least-privilege limits the set of files or directories any subject can affect, shrinking the blast radius of a path-control flaw.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect path-traversal issues but does not itself implement preventive controls.
Secure development lifecycle mandates input validation and path-handling controls that directly prevent external file/path manipulation.
Application security requirements explicitly call for controls against untrusted input influencing file operations.
Secure architecture principles discourage unsafe path construction but do not prescribe concrete file-name controls.
Secure coding standards require canonicalization, allow-listing, and bounds checks on file paths, directly eliminating CWE-73.
Information access restriction limits which files can be reached, indirectly reducing impact of path manipulation.