PT-2025-44715 · WordPress · Tablesome Table – Contact Form Db – Wpforms

·

CVE-2025-11499

·

Published

2025-11-01

·

Updated

2025-11-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent versions up to and including 1.1.32
Description The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is susceptible to arbitrary file uploads. This is due to a lack of file type validation within the set featured image from external url() function. This allows unauthenticated attackers to upload arbitrary files to the affected server. In configurations where unauthenticated users have the ability to add featured images, this could lead to remote code execution.
Recommendations Versions up to and including 1.1.32: Update to a version beyond 1.1.32.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11499

Affected Products

Tablesome Table – Contact Form Db – Wpforms