AI description
CVE-2025-7341 is a vulnerability found in the HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress. It affects versions up to and including 2.2.1. The vulnerability lies in the `tempfiledelete()` function, where insufficient file path validation allows unauthenticated attackers to delete arbitrary files on the server. This arbitrary file deletion vulnerability can lead to remote code execution if an attacker deletes a critical file such as `wp-config.php`. A patch has been released in version 2.2.2 of the plugin to address this issue by improving file path validation. Users are advised to update to the latest version as soon as possible.
- Description
- The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
- Source
- security@wordfence.com
- NVD status
- Analyzed
- Products
- download_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-269
- Hype score
- Not currently trending
🚨Vulnerabilidades críticas en un plugin de WordPress dejan 10.000 sitios vulnerables ➡️ HT Contact Form Widget for Elementor Page Builder & Gutenberg Blocks & Form Builder ⚠️ CVE-2025-7340 ⚠️ CVE-2025-7341 https://t.co/mytav1Kyls
@elhackernet
31 Jul 2025
5686 Impressions
41 Retweets
97 Likes
21 Bookmarks
2 Replies
1 Quote
CVE-2025-7341 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie… https://t.co/ABcizgdw8X
@CVEnew
15 Jul 2025
661 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-7341: CRITICAL] WordPress plugin HT Contact Form Widget for Elementor & Gutenberg is at risk of file deletion due to a flaw in temp_file_delete(). Unauthenticated attackers may delete files, posing s...#cve,CVE-2025-7341,#cybersecurity https://t.co/SFhFz57QfQ https:
@CveFindCom
15 Jul 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hasthemes:download_contact_form_7_widget_for_elementor_page_builder_\\&_gutenberg_blocks:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "867698F7-BEA0-4E88-8894-A233A040E08A",
"versionEndExcluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
]