Arbitrary File Moving Vulnerability in HT Contact Form Widget for WordPress
CVE-2025-7360

9.1CRITICAL

What is CVE-2025-7360?

The HT Contact Form Widget for Elementor Page Builder and Gutenberg Blocks is susceptible to an arbitrary file moving vulnerability due to inadequate file path validation in the handle_files_upload() function present in all versions up to and including 2.2.1. This security flaw could allow unauthenticated attackers to move sensitive files on the server, potentially leading to serious consequences such as remote code execution if a critical file, like wp-config.php, is manipulated.

Affected Version(s)

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. * <= 2.2.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tan Phat
.
CVE-2025-7360 : Arbitrary File Moving Vulnerability in HT Contact Form Widget for WordPress