WordPress Redirection for Contact Form 7 Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Redirection for Contact Form 7 plugin for WordPress, affecting all versions through 3.2.4. The issue arises from inadequate file path validation in the delete_associated_files function, enabling unauthenticated attackers to delete arbitrary files on the server. This vulnerability could easily lead to remote code execution if a critical file, such as wp-config.php, is deleted.

Impact

Exploitation of this vulnerability could result in unauthorized deletion of files on the server, potentially leading to remote code execution if a sensitive file is removed.

Remediation

Users are advised to update the Redirection for Contact Form 7 plugin to version 3.2.5 or a newer patched version.

Added: Aug 20, 2025, 3:19 AM
Updated: Aug 20, 2025, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
9.0
remediation
7.7
relevance
0.4
threat
3.2
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.