PT-2025-50912 · WordPress · Pdf For Contact Form 7 + Drag/Drop Template Builder

Abhirup Konwar

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-14074

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress versions through 6.3.3
Description The software contains a flaw that allows unauthorized post duplication. A missing capability check within the rednumber duplicate function enables authenticated attackers with Subscriber-level access or higher to duplicate posts, even those that are password-protected or private.
Recommendations Update to a version beyond 6.3.3.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14074

Affected Products

Pdf For Contact Form 7 + Drag/Drop Template Builder