CVE-2025-3515 affects the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin in all versions up to and including 1.3.8.9. The vulnerability is caused by insufficient server-side file type validation in the plugin's upload handling, allowing attackers to bypass the plugin's blacklist-based restrictions and upload dangerous file types such as .phar. Because the control relies on inadequate filtering rather than strict allowlisting and robust validation, unauthenticated attackers can place attacker-controlled files on the target server. In environments where uploaded .phar files are treated as executable PHP content, this can lead to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a working exploit for CVE-2025-3515, a remote code execution (RCE) vulnerability in the 'Drag and Drop Multiple File Upload for Contact Form 7' WordPress plugin (versions <=1.3.8.9, possibly 1.3.9.0). The vulnerability allows unauthenticated attackers to upload arbitrary PHP files (such as .phar, .php5, .inc) due to insufficient file extension blacklisting, leading to remote code execution. The repository contains two main exploit scripts: - 'exploit.py': A feature-rich exploit that checks target accessibility, detects the vulnerable plugin, searches for suitable Contact Form 7 forms, uploads a randomly generated PHP webshell using various file extensions, and provides an interactive shell for command execution. - 'v1exploit.py': A streamlined version that performs similar steps, focusing on .phar payloads and providing an interactive shell if exploitation is successful. Both scripts target the '/wp-admin/admin-ajax.php' endpoint with the 'dnd_codedropz_upload' action to upload the malicious file. They then attempt to locate the uploaded webshell in common directories under '/wp-content/uploads/' or the plugin's own upload directory. If successful, the attacker can execute arbitrary system commands via HTTP requests to the webshell. The README provides technical details, detection advice, and references. The exploit is operational, providing a working webshell payload and interactive shell capability. No fake or destructive code is present; the scripts are focused on exploitation and post-exploitation access.
This repository provides two Python exploit scripts (exploit.py and v1exploit.py) targeting CVE-2025-3515, a remote code execution vulnerability in the 'Drag and Drop Multiple File Upload for Contact Form 7' WordPress plugin (versions <=1.3.8.9, possibly 1.3.9.0). The vulnerability allows unauthenticated attackers to upload arbitrary files (such as PHP webshells) via the plugin's file upload functionality, bypassing extension blacklists. Both scripts automate the exploitation process: they check for the presence and version of the vulnerable plugin, attempt to locate a suitable Contact Form 7 form, generate a PHP webshell payload (e.g., a .phar file containing code to execute system commands), and upload it to the server. After upload, the scripts attempt to locate the webshell in common upload directories and provide an interactive shell for the attacker to execute commands remotely. The main endpoints involved are the plugin's directory, the vulnerable PHP file, the admin-ajax.php endpoint for uploads, and the various upload directories where the webshell may be placed. The exploit is operational, providing a working webshell if successful, and is not part of a larger exploitation framework. The repository is well-structured, with clear documentation and two alternative exploit implementations.
This repository targets CVE-2025-3515, a vulnerability in the 'drag-and-drop-multiple-file-upload-contact-form-7' WordPress plugin (<=1.3.8.9) that allows arbitrary file uploads, leading to remote code execution. The repository contains two main Python scripts: - 'checker.py': Scans a list of target URLs to detect the presence of the vulnerable plugin by checking for its readme file. It uses multithreading for efficiency and writes detected sites to 'CF7.txt'. - 'exploit.py': Automates the exploitation process. It writes a custom PHP webshell to disk, then uploads this shell to each target using the plugin's vulnerable AJAX endpoint. If successful, it extracts and records the URL of the uploaded shell. The shell, when accessed, fetches and executes additional PHP code from a remote GitHub URL, providing the attacker with remote code execution on the target server. The exploit is operational and automates both detection and exploitation. It requires a list of target URLs and outputs the URLs of successfully uploaded shells. The main attack vector is network-based, targeting WordPress sites with the vulnerable plugin exposed. The repository is not part of a known exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.