CVE-2025-14800: Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'movefiletoupload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server. If 'allowurlfopen' is set to 'On', it is possible to upload a remote file to the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14800?
CVE-2025-14800 is considered a critical vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2025-14800?
To fix CVE-2025-14800, update the Redirection for Contact Form 7 plugin to a version later than 3.2.7.
Who is affected by CVE-2025-14800?
Any user of the Redirection for Contact Form 7 plugin on WordPress up to and including version 3.2.7 is affected by CVE-2025-14800.
What type of attacks can CVE-2025-14800 enable?
CVE-2025-14800 can enable unauthenticated attackers to upload arbitrary files, leading to further exploitation.
Is authentication required to exploit CVE-2025-14800?
No, CVE-2025-14800 can be exploited by unauthenticated attackers, making it particularly dangerous.