- Description
- The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
- Source
- security@wordfence.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-269
- Hype score
- Not currently trending
CVE-2025-7341 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie… https://t.co/ABcizgdw8X
@CVEnew
15 Jul 2025
661 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-7341: CRITICAL] WordPress plugin HT Contact Form Widget for Elementor & Gutenberg is at risk of file deletion due to a flaw in temp_file_delete(). Unauthenticated attackers may delete files, posing s...#cve,CVE-2025-7341,#cybersecurity https://t.co/SFhFz57QfQ https:
@CveFindCom
15 Jul 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hasthemes:download_contact_form_7_widget_for_elementor_page_builder_\\&_gutenberg_blocks:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "867698F7-BEA0-4E88-8894-A233A040E08A",
"versionEndExcluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
]