Arbitrary File Deletion in Extensions For CF7 Plugin for WordPress
CVE-2025-7645
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 July 2025
What is CVE-2025-7645?
The Extensions For CF7 plugin for WordPress suffers from a vulnerability that allows unauthenticated attackers to delete arbitrary files on the server due to inadequate validation of file paths in the 'delete-file' function. This occurs when an administrator deletes a submission, potentially allowing for deletion of critical files such as wp-config.php, which could lead to further issues like remote code execution.
Affected Version(s)
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) * <= 3.2.8