CVE-2026-14325Disclosure

LOWCVSS 3.5 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 308-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14325 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in f… https://www.cve.org/CVERecord?id=CVE-2026-14325 ----- Traducción: CVE-2026-14325 La … http://infoflow.cloud`

    Post summary

    The post simply announces CVE-2026-14325 with a brief technical detail about an unescaped setting in the Contact Form 7 plugin, without providing exploit code, patch information, or evidence of active use.

    0101159
    102 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-14325 Stored XSS in Contact Form 7 Plugin Due to Unescaped Setting https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14325

    Post summary

    The entry reports a stored XSS flaw in Contact Form 7 but offers no PoC, exploit code, evidence of active exploitation, or patch information.

    00000107
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14325 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in f… https://www.cve.org/CVERecord?id=CVE-2026-14325

    Post summary

    CVE-2026-14325 affects the Drag and Drop Multiple File Upload plugin for Contact Form 7 by failing to escape a setting used as an HTML tag name, potentially enabling XSS attacks; no PoC, exploit, or patch details are provided.

    00000788
    58.0K followersView on X

Explore more