
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64231 is an Unrestricted File Upload vulnerability (CWE-434) in the WordPress Contact Form 7 PDF, Google Sheet & Database plugin by RedefiningTheWeb, allowing unauthenticated attackers to upload malicious files to affected WordPress sites. All plugin versions up to and including 3.0.0 are affected; version 3.1.0 contains the fix. The vulnerability was reported by researcher 0xd4rk5id3 on September 28, 2025, and published by Patchstack on October 28, 2025, with NVD publication on December 18, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, and 9.9 (Critical) per Patchstack (Patchstack).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types submitted through the Contact Form 7 integration. An unauthenticated attacker can abuse the file upload functionality exposed by the plugin — likely a form attachment handler — to upload arbitrary file types, including PHP web shells or other executable scripts, without requiring any authentication or elevated privileges. No user interaction is required, and the attack is network-accessible with low complexity. The required privilege level noted by Patchstack is "Subscriber," suggesting the upload endpoint may be accessible to low-privileged or unauthenticated users (Patchstack).
Successful exploitation allows an unauthenticated attacker to upload malicious files — such as PHP backdoors or web shells — directly to the WordPress server, enabling full remote code execution. This results in high confidentiality, integrity, and availability impacts: attackers can exfiltrate sensitive data, modify or delete site content, install persistent backdoors, and potentially pivot to other systems on the hosting environment. Patchstack notes this class of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).
As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.018% (0.000180), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates it as "highly dangerous and expected to become exploited," consistent with the unauthenticated, network-accessible attack vector and the history of similar WordPress plugin vulnerabilities being weaponized in mass campaigns.
readme.txt file at https://target.com/wp-content/plugins/rtwwcfp-wordpress-contact-form-7-pdf/readme.txt.shell.php containing <?php system($_GET['cmd']); ?>) and submit it via an HTTP POST request to the plugin's file upload handler, bypassing any client-side restrictions.wp-content/uploads/ or a plugin-specific directory).https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary OS commands on the server, establishing a foothold for further post-exploitation activities such as credential harvesting, lateral movement, or persistent backdoor installation (Patchstack)./wp-admin/admin-ajax.php) or plugin-specific upload handlers with multipart form data containing .php, .phtml, .phar, or other executable file extensions; outbound connections from the web server process to unknown external IPs..php files (especially with names like shell.php, cmd.php, upload.php, or random strings) appearing in wp-content/uploads/ or plugin directories such as wp-content/plugins/rtwwcfp-wordpress-contact-form-7-pdf/; newly created files with web shell signatures (e.g., system(), exec(), passthru(), base64_decode() patterns)..php files in upload directories; HTTP 200 responses to requests for .php files in wp-content/uploads/.bash, sh, curl, wget, or python); unexpected outbound network connections initiated by the PHP-FPM or web server process.The vendor has released version 3.1.0 of the WordPress Contact Form 7 PDF, Google Sheet & Database plugin, which resolves this vulnerability. Site administrators should update the plugin to version 3.1.0 or later immediately via the WordPress admin dashboard or by downloading from the plugin repository. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploit attempts until the plugin is updated. Additional hardening steps include deploying a Web Application Firewall (WAF) configured to block suspicious file uploads, restricting the types of files accepted by upload handlers at the server level (e.g., via .htaccess or Nginx configuration), and auditing the wp-content/uploads/ directory for any unexpected PHP files (Patchstack).
The vulnerability was discovered by independent researcher 0xd4rk5id3 and disclosed through Patchstack's coordinated vulnerability disclosure program, with the advisory published on October 28, 2025. Patchstack flagged it as a high-priority issue expected to be targeted in mass-exploit campaigns, consistent with their broader warnings about arbitrary file upload vulnerabilities in WordPress plugins. Social media activity was observed on Mastodon (TheHackerWire) and Bluesky shortly after NVD publication in December 2025, indicating moderate community awareness (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."