CVE-2025-7340: HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the tempfileupload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7340?
CVE-2025-7340 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2025-7340?
To fix CVE-2025-7340, users should update the HT Contact Form Widget to version 2.2.2 or later, which includes file type validation.
What versions of the HT Contact Form Widget are affected by CVE-2025-7340?
CVE-2025-7340 affects all versions of the HT Contact Form Widget for WordPress up to and including version 2.2.1.
What types of files can be uploaded due to CVE-2025-7340?
Due to CVE-2025-7340, the vulnerability allows attackers to upload arbitrary files, potentially leading to unauthorized access or execution.
Is there a risk of exploitation for CVE-2025-7340?
Yes, CVE-2025-7340 presents a significant risk of exploitation, as it allows attackers to upload malicious files to the server.