Unauthorized Post Duplication in PDF for Contact Form 7 Plugin by WordPress
CVE-2025-14074

5.3MEDIUM

What is CVE-2025-14074?

The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is susceptible to an authorization bypass, which permits authenticated users, specifically those with Subscriber-level access and higher, to duplicate any post. This flaw arises from a missing capability check in the 'rednumber_duplicate' function across all versions up to and including 6.3.3. Consequently, attackers can replicate posts, including those protected by passwords or marked as private, thus severely compromising the content integrity of affected sites.

Affected Version(s)

PDF for Contact Form 7 + Drag and Drop Template Builder * <= 6.3.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhirup Konwar
.
CVE-2025-14074 : Unauthorized Post Duplication in PDF for Contact Form 7 Plugin by WordPress