Arbitrary File Deletion Vulnerability in HT Contact Form Widget for WordPress
CVE-2025-7341

9.1CRITICAL

What is CVE-2025-7341?

The HT Contact Form Widget for Elementor Page Builder and Gutenberg Blocks suffers from a vulnerability that allows unauthenticated attackers to exploit insufficient file path validation in the temp_file_delete() function. This flaw is present in all versions up to and including 2.2.1. By exploiting this vulnerability, it is possible for attackers to delete arbitrary files on the server. If sensitive files are targeted, such as wp-config.php, this can lead to severe security breaches, including unauthorized remote code execution, posing a significant risk to WordPress installations.

Affected Version(s)

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. * <= 2.2.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.
CVE-2025-7341 : Arbitrary File Deletion Vulnerability in HT Contact Form Widget for WordPress