Known vulnerabilities in Drag and Drop Multiple File Upload for WooCommerce
Drag and Drop Multiple File Uploader is a simple, straightforward WordPress plugin extension for WooCommerce.
4Reported vulnerabilities
9.8Highest CVSS score
1.1.8Latest version
5,000+Active installs
What to do now
Update Drag and Drop Multiple File Upload for WooCommerce to 1.1.8 or later.
4 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-4403 | Critical | 2.1% | 0 to 1.1.6 (inclusive) | 1.1.7 |
May 9, 2025 |
| CVE-2025-2941 | Critical | 1.7% | 0 to 1.1.4 (inclusive) | 1.1.5 |
April 5, 2025 |
| CVE-2026-16054 | Critical | 0.3% | 1.1.7 and earlier | 1.1.8 |
July 30, 2026 |
| CVE-2022-45377 | Medium | 0.6% | 1.0.8 and earlier | 1.0.9 |
February 23, 2023 |