WP Clinic
Log in Sign up

CVE · High

CVE-2025-14800 — Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14800 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8 Unrestricted Upload of File with Dangerous Type High 8.1 < 3.2.8 3.2.8 2025-12-20

CVE-2025-14800

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server. If 'allow_url_fopen' is set to 'On', it is possible to upload a remote file to the server.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.