PT-2025-44715 · WordPress · Tablesome Table – Contact Form Db – Wpforms

Talal Nasraddeen

·

Published

2025-11-01

·

Updated

2025-11-01

·

CVE-2025-11499

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent versions up to and including 1.1.32
Description The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is susceptible to arbitrary file uploads. This is due to a lack of file type validation within the set featured image from external url() function. This allows unauthenticated attackers to upload arbitrary files to the affected server. In configurations where unauthenticated users have the ability to add featured images, this could lead to remote code execution.
Recommendations Versions up to and including 1.1.32: Update to a version beyond 1.1.32.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11499

Affected Products

Tablesome Table – Contact Form Db – Wpforms