CVE-2025-11499: Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the setfeaturedimagefromexternalurl() function in all versions up to, and including, 1.1.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible in configurations where unauthenticated users have been provided with a method for adding featured images, and the workflow trigger is created.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11499?
CVE-2025-11499 is classified as a critical vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2025-11499?
To fix CVE-2025-11499, update the affected plugins to version 1.1.33 or later where the file type validation has been implemented.
Which versions are affected by CVE-2025-11499?
CVE-2025-11499 affects all versions of the Tablesome Table – Contact Form DB, WPForms, CF7, Gravity, Forminator, and Fluent plugins up to and including 1.1.32.
What are the potential impacts of CVE-2025-11499?
The impacts of CVE-2025-11499 include unauthorized file uploads, which could lead to remote code execution or data breaches.
Is CVE-2025-11499 specific to any particular WordPress environment?
CVE-2025-11499 is not limited to a specific WordPress environment; it affects all installations using the vulnerable plugins regardless of their setup.