References https://nvd.nist.gov/vuln/detail/CVE-2025-6220 https://github.com/advisories/GHSA-mqp3-fvx6-rp7p https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-addons-for-contact-form-7/ultimate-addons-for-contact-form-7-3512-authenticated-administrator-arbitrary-file-upload-via-save-options https://cve.imfht.com/detail/CVE-2025-6220 https://ryankozak.com/posts/cve-2025-6220/ https://devhub.checkmarx.com/cve-details/cve-2025-6220/ https://avd.aquasec.com/nvd/2025/cve-2025-6220/ https://cve.imfht.com/poc_detail/ef10371fb67f08f40a95eaf0b83b10d208308c20?lang=en
Related VulnerabilitiesPoCCVE-2026-4257: WordPress Contact Form by Supsystic - Server-Side Template InjectionWordPress Contact-form-by-supsystic SSTI注入(CVE-2026-4257)PoCCVE-2025-14155: Premium Addons for Elementor - Unauthenticated Information DisclosurePoCwp-cf7-data-source-fpd: WordPress Data Source for Contact Form 7 - Full Path Disclosure孚盟云CRM /m/Dingding/Ajax/AjaxBusinessPrice.ashx GetContactEmail SQL 注入漏洞PoCwp-contact-form-7-fpd: WordPress Contact Form 7 - Full Path DisclosurePoCwp-contact-form-fpd: WordPress Contact Form - Full Path Disclosure孚盟云CRM /m/Dingding/Ajax/AjaxBusinessPrice.ashx GetContactEmailByFid SQL 注入漏洞PoCCVE-2020-13125: Ultimate Addons for Elementor <= 1.24.1 - Registration BypassPoCCVE-2021-4448: Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization