CVE-2025-7341

Published Jul 15, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-7341 is a vulnerability found in the HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress. It affects versions up to and including 2.2.1. The vulnerability lies in the `tempfiledelete()` function, where insufficient file path validation allows unauthenticated attackers to delete arbitrary files on the server. This arbitrary file deletion vulnerability can lead to remote code execution if an attacker deletes a critical file such as `wp-config.php`. A patch has been released in version 2.2.2 of the plugin to address this issue by improving file path validation. Users are advised to update to the latest version as soon as possible.

Description
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Source
security@wordfence.com
NVD status
Analyzed
Products
download_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-269

Social media

Hype score
Not currently trending

Configurations