External risk intelligence

WordPress Contact Form 7 PDF Google Sheet Database Unrestricted File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2025-64231

The vulnerability exists in a WordPress plugin designed to handle contact forms. WordPress sites and their associated form submission endpoints are commonly deployed as public-facing web services, making them directly reachable from the internet for interaction with site visitors.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress plugin that handles contact form submissions, allowing attackers to upload malicious files. The issue has a critical severity rating, indicating a high potential for impact if exploited. The main concern is to confirm if this specific plugin is in use and if it's exposed to potential threats.

  • Malicious file uploads are possible.
  • Critical severity requires attention.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could upload malicious files to a WordPress site through the Contact Form 7 PDF, Google Sheet & Database plugin. This vulnerability allows an authenticated user with low privileges to bypass security checks and upload dangerous file types. Once a malicious file is uploaded, it could lead to the compromise of the entire website.

  • Authenticated low-privilege user access required.
  • Uploading a dangerous file type triggers the vulnerability.
  • Allows arbitrary file upload, potentially compromising the site.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload dangerous files to the affected WordPress site, potentially impacting service behavior when a logged-in user interacts with the contact form.

  • Malicious files could be uploaded.
  • Uploads occur via the contact form.
  • Service behavior may be altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability likely impacts WordPress sites using the Contact Form 7 PDF, Google Sheet & Database plugin. The first step is to identify all instances of this plugin, confirm their exposure and criticality, and then engage the appropriate team for remediation.

  • Identify plugin owners and scope.
  • Verify plugin reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the RedefiningTheWeb Contact Form 7 PDF plugin?

This is a WordPress plugin used to extend the functionality of Contact Form 7. It allows site administrators to automatically save form submissions into PDF documents, Google Sheets, or directly into a database for easier data management and reporting.

How does CWE-434 relate to CVE-2025-64231?

This CVE falls under CWE-434, which is the Unrestricted Upload of File with Dangerous Type. It means the software does not sufficiently verify the format or contents of files uploaded through it, allowing users to submit malicious code disguised as legitimate files.

Do I need to be an admin to trigger this vulnerability?

No, you do not need administrative privileges to trigger this. The flaw allows a user with lower-level authenticated access to bypass security checks that should restrict file uploads, meaning regular registered users could potentially exploit the weakness.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a 'Likely' risk because the plugin is designed for public-facing contact forms. Since WordPress sites are generally accessible from the internet to collect user feedback, the plugin's endpoints are inherently exposed.

What should I do if I am running this plugin?

First, conduct an audit to confirm if your WordPress installation uses this specific plugin. Once identified, evaluate the plugin's necessity for your site's operations. If you find it installed, coordinate with your technical team to prioritize removing or replacing it.

References