CVE-2025-64231: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64231 is an Unrestricted File Upload vulnerability (CWE-434) in the WordPress Contact Form 7 PDF, Google Sheet & Database plugin by RedefiningTheWeb, allowing unauthenticated attackers to upload malicious files to affected WordPress sites. All plugin versions up to and including 3.0.0 are affected; version 3.1.0 contains the fix. The vulnerability was reported by researcher 0xd4rk5id3 on September 28, 2025, and published by Patchstack on October 28, 2025, with NVD publication on December 18, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, and 9.9 (Critical) per Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types submitted through the Contact Form 7 integration. An unauthenticated attacker can abuse the file upload functionality exposed by the plugin — likely a form attachment handler — to upload arbitrary file types, including PHP web shells or other executable scripts, without requiring any authentication or elevated privileges. No user interaction is required, and the attack is network-accessible with low complexity. The required privilege level noted by Patchstack is "Subscriber," suggesting the upload endpoint may be accessible to low-privileged or unauthenticated users (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to upload malicious files — such as PHP backdoors or web shells — directly to the WordPress server, enabling full remote code execution. This results in high confidentiality, integrity, and availability impacts: attackers can exfiltrate sensitive data, modify or delete site content, install persistent backdoors, and potentially pivot to other systems on the hosting environment. Patchstack notes this class of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.018% (0.000180), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates it as "highly dangerous and expected to become exploited," consistent with the unauthenticated, network-accessible attack vector and the history of similar WordPress plugin vulnerabilities being weaponized in mass campaigns.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Contact Form 7 PDF, Google Sheet & Database" plugin version ≤ 3.0.0 using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/rtwwcfp-wordpress-contact-form-7-pdf/readme.txt.
  2. Locate the upload endpoint: Identify the form submission endpoint used by the plugin for file attachments, typically a WordPress AJAX handler or a direct form POST endpoint exposed by the plugin.
  3. Craft malicious upload request: Prepare a PHP web shell (e.g., shell.php containing <?php system($_GET['cmd']); ?>) and submit it via an HTTP POST request to the plugin's file upload handler, bypassing any client-side restrictions.
  4. Confirm upload success: Check the server response for a file path or URL indicating where the uploaded file was stored (e.g., within wp-content/uploads/ or a plugin-specific directory).
  5. Execute remote code: Access the uploaded web shell via its URL (e.g., https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary OS commands on the server, establishing a foothold for further post-exploitation activities such as credential harvesting, lateral movement, or persistent backdoor installation (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or plugin-specific upload handlers with multipart form data containing .php, .phtml, .phar, or other executable file extensions; outbound connections from the web server process to unknown external IPs.
  • File System: Unexpected .php files (especially with names like shell.php, cmd.php, upload.php, or random strings) appearing in wp-content/uploads/ or plugin directories such as wp-content/plugins/rtwwcfp-wordpress-contact-form-7-pdf/; newly created files with web shell signatures (e.g., system(), exec(), passthru(), base64_decode() patterns).
  • Logs: Web server access logs showing POST requests to the plugin's upload endpoint followed shortly by GET requests to newly created .php files in upload directories; HTTP 200 responses to requests for .php files in wp-content/uploads/.
  • Process: Unusual child processes spawned by the web server process (e.g., Apache/Nginx spawning bash, sh, curl, wget, or python); unexpected outbound network connections initiated by the PHP-FPM or web server process.

Mitigation and workarounds

The vendor has released version 3.1.0 of the WordPress Contact Form 7 PDF, Google Sheet & Database plugin, which resolves this vulnerability. Site administrators should update the plugin to version 3.1.0 or later immediately via the WordPress admin dashboard or by downloading from the plugin repository. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploit attempts until the plugin is updated. Additional hardening steps include deploying a Web Application Firewall (WAF) configured to block suspicious file uploads, restricting the types of files accepted by upload handlers at the server level (e.g., via .htaccess or Nginx configuration), and auditing the wp-content/uploads/ directory for any unexpected PHP files (Patchstack).

Community reactions

The vulnerability was discovered by independent researcher 0xd4rk5id3 and disclosed through Patchstack's coordinated vulnerability disclosure program, with the advisory published on October 28, 2025. Patchstack flagged it as a high-priority issue expected to be targeted in mass-exploit campaigns, consistent with their broader warnings about arbitrary file upload vulnerabilities in WordPress plugins. Social media activity was observed on Mastodon (TheHackerWire) and Bluesky shortly after NVD publication in December 2025, indicating moderate community awareness (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management