CVE-2025-7341Disclosure(hasthemes / download_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • download_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
download_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-7341: HT Contact Form Widget For Elemen... Unauthenticated file deletion via path traversal in temp_file_delete() - nuke wp-config.php for instant RCE on 200k+ Wor... https://zerodaysignal.com/vulnerability/CVE-2025-7341 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2025-7341, outlining a path‑traversal based file‑deletion flaw that can lead to remote code execution on WordPress sites, yet offers no PoC, exploit code, active exploitation evidence, or patch details.

    00000293
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphasthemesdownload_contact_form_7_widget_for_elementor_page_builder_\&_gutenberg_blocks-wordpress-

Explore more