Arbitrary File Upload Vulnerability in Contact Form 7 Plugin for WordPress
CVE-2025-14800

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 December 2025

What is CVE-2025-14800?

The Redirect for Contact Form 7 plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation in the 'move_file_to_upload' function. This vulnerability allows unauthenticated attackers to potentially upload malicious files to the server hosting the affected site, especially when 'allow_url_fopen' is enabled. All versions up to and including 3.2.7 are implicated, highlighting the necessity for users to review and secure their installations promptly.

Affected Version(s)

Redirection for Contact Form 7 * <= 3.2.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LionTree
.
CVE-2025-14800 : Arbitrary File Upload Vulnerability in Contact Form 7 Plugin for WordPress