Arbitrary File Upload Vulnerability in Contact Form 7 Plugin for WordPress
CVE-2025-14800
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 December 2025
What is CVE-2025-14800?
The Redirect for Contact Form 7 plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation in the 'move_file_to_upload' function. This vulnerability allows unauthenticated attackers to potentially upload malicious files to the server hosting the affected site, especially when 'allow_url_fopen' is enabled. All versions up to and including 3.2.7 are implicated, highlighting the necessity for users to review and secure their installations promptly.
Affected Version(s)
Redirection for Contact Form 7 * <= 3.2.7