Arbitrary File Moving Vulnerability in HT Contact Form Widget for WordPress
CVE-2025-7360
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 July 2025
What is CVE-2025-7360?
The HT Contact Form Widget for Elementor Page Builder and Gutenberg Blocks is susceptible to an arbitrary file moving vulnerability due to inadequate file path validation in the handle_files_upload() function present in all versions up to and including 2.2.1. This security flaw could allow unauthenticated attackers to move sensitive files on the server, potentially leading to serious consequences such as remote code execution if a critical file, like wp-config.php, is manipulated.
Affected Version(s)
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. * <= 2.2.1