Description
Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0.
Published: 2025-12-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unrestricted file upload flaw in the RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database plugin. The plugin allows users to submit files without validating their type, letting the attacker upload a file that can be executed on the server. If the uploaded file is a web‑accessible script or PHP, it can run arbitrary code, compromising the entire site and potentially the hosting environment. The underlying weakness is identified as CWE‑434, which indicates an unsafe handling of user‑supplied file names and content.

Affected Systems

The flaw affects any WordPress installation that has the RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database plugin installed with a version equal to or less than 3.0.0. No sub‑version or patch details are supplied, so all releases up to 3.0.0 are considered vulnerable.

Risk and Exploitability

The CVSS base score of 9.9 classifies this as critical, and the EPSS score remains below 1 %, indicating a low but non‑zero probability of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no confirmed exploits to date. An attacker would most likely exploit the site by submitting a malicious file through the plugin’s upload interface, which typically requires authenticated access to the WordPress dashboard or the public form page. Successful exploitation grants the attacker local code execution on the web server, with the potential to compromise confidentiality, integrity, and availability at the site or host level.

Generated by OpenCVE AI on April 29, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RedefiningTheWeb’s WordPress Contact Form 7 PDF, Google Sheet & Database plugin to a version newer than 3.0.0, which removes the unsafe upload handling.
  • If an immediate upgrade is infeasible, disable or restrict the plugin’s file upload feature by setting permission limits or removing upload endpoints entirely.
  • Implement server‑side file type validation and configure the web server to prevent execution of files stored in the upload directory.

Generated by OpenCVE AI on April 29, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Redefiningtheweb
Redefiningtheweb wordpress Contact Form 7 Pdf Google Sheet Database
Wordpress
Wordpress wordpress
Vendors & Products Redefiningtheweb
Redefiningtheweb wordpress Contact Form 7 Pdf Google Sheet Database
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0.
Title WordPress WordPress Contact Form 7 PDF, Google Sheet & Database plugin <= 3.0.0 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References

Subscriptions

Redefiningtheweb Wordpress Contact Form 7 Pdf Google Sheet Database
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:11.320Z

Reserved: 2025-10-29T03:08:07.244Z

Link: CVE-2025-64231

cve-icon Vulnrichment

Updated: 2025-12-18T14:32:43.499Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:12.670

Modified: 2026-04-27T16:16:35.953

Link: CVE-2025-64231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses