CVE-2020-12800 is a vulnerability in the drag-and-drop-multiple-file-upload-contact-form-7 WordPress plugin prior to version 1.3.3.3. The vulnerability allows attackers to bypass file type restrictions by setting the supported_type parameter to 'php%' and uploading a file with a '.php%' extension. This results in unrestricted file upload, enabling remote code execution on the affected WordPress instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/multi/http/wp_dnd_mul_file_rce.rb) targeting a remote code execution vulnerability (CVE-2020-12800) in the 'Drag and Drop Multi File Upload - Contact Form 7' WordPress plugin (versions prior to 1.3.4). The exploit abuses a file extension bypass (using a trailing '%') to upload a PHP payload via the /wp-admin/admin-ajax.php endpoint. The module then attempts to trigger the payload by accessing it in the uploads directory. The exploit is unauthenticated and does not require prior access to the WordPress site. The code is written in Ruby and is designed to be run within the Metasploit framework. The main file implements all logic for exploitation, including nonce retrieval, payload upload, and execution. The exploit provides remote code execution as the web server user if successful.
This repository contains a proof-of-concept exploit for CVE-2020-12800, targeting the 'Drag and Drop Multiple File Upload - Contact Form 7' WordPress plugin version 1.3.3.2. The exploit is implemented in a single Python script ('exploit.py') and is accompanied by a README.md with background information and usage notes. The exploit works by bypassing file type restrictions to upload a PHP webshell to the server, which can then be accessed and used to execute arbitrary commands remotely. The script automates the process of finding the required AJAX nonce, crafting a multipart/form-data POST request to upload the payload, and locating the uploaded file on the server. Once the webshell is found, the script provides an interactive command execution interface. The main endpoints involved are the plugin's AJAX handler ('/wp-admin/admin-ajax.php') for the upload and the uploads directory ('/wp-content/uploads/wp_dndcf7_uploads/') for accessing the webshell. The exploit does not require authentication and is effective against unpatched installations of the vulnerable plugin.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.