Unauthorized Post Duplication in PDF for Contact Form 7 Plugin by WordPress
CVE-2025-14074
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-14074?
The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is susceptible to an authorization bypass, which permits authenticated users, specifically those with Subscriber-level access and higher, to duplicate any post. This flaw arises from a missing capability check in the 'rednumber_duplicate' function across all versions up to and including 6.3.3. Consequently, attackers can replicate posts, including those protected by passwords or marked as private, thus severely compromising the content integrity of affected sites.
Affected Version(s)
PDF for Contact Form 7 + Drag and Drop Template Builder * <= 6.3.3