CVE-2025-24695: WordPress Extensions For CF7 Plugin <= 3.2.0 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Server Side Request Forgery.This issue affects Extensions For CF7: from n/a through <= 3.2.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24695?
CVE-2025-24695 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-24695?
To fix CVE-2025-24695, update HasThemes Extensions For CF7 to version 3.2.1 or later.
What applications are affected by CVE-2025-24695?
CVE-2025-24695 affects HasThemes Extensions For CF7 versions up to and including 3.2.0.
What is a Server-Side Request Forgery vulnerability?
A Server-Side Request Forgery (SSRF) vulnerability allows an attacker to send crafted requests from the server, potentially leading to unauthorized access to internal systems.
Can CVE-2025-24695 be exploited remotely?
Yes, CVE-2025-24695 can be exploited remotely if an attacker is able to send requests that leverage the SSRF vulnerability.