CVE-2025-6220: Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveoptions' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6220?
CVE-2025-6220 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2025-6220?
To fix CVE-2025-6220, update the Ultra Addons for Contact Form 7 plugin to version 3.5.13 or later.
Who is affected by CVE-2025-6220?
Users of the Ultra Addons for Contact Form 7 and Ultimate Addons for Contact Form 7 plugins up to version 3.5.12 are affected by CVE-2025-6220.
What types of attacks can CVE-2025-6220 enable?
CVE-2025-6220 allows authenticated attackers with Administrator-level access to upload arbitrary files on the WordPress site.
What is the nature of the vulnerability in CVE-2025-6220?
CVE-2025-6220 is a vulnerability due to missing file type validation in the 'save_options' function.