References https://nvd.nist.gov/vuln/detail/CVE-2025-7340 https://www.wordfence.com/blog/2025/07/10000-wordpress-sites-affected-by-critical-vulnerabilities-in-ht-contact-form-wordpress-plugin/ https://github.com/Nxploited/CVE-2025-7340 https://www.sentinelone.com/vulnerability-database/cve-2025-7340/ https://www.wordfence.com/threat-intel/vulnerabilities/id/f0cb666b-bfab-492f-a74e-11dc9b171136?source=cve https://patchstack.com/database/wordpress/plugin/ht-contactform/vulnerability/wordpress-ht-contact-form-widget-for-elementor-page-builder-gutenberg-blocks-form-builder-plugin-2-2-1-unauthenticated-arbitrary-file-upload-vulnerability https://github.com/advisories/GHSA-85f4-4cwm-5xmr https://wpscan.com/vulnerability/91f39d58-1379-4908-bdeb-9c9bce39fb2c/ https://app.opencve.io/cve/CVE-2025-7340 https://www.ameeba.com/blog/cve-2025-7340-critical-arbitrary-file-upload-vulnerability-in-ht-contact-form-widget-for-wordpress/
Related VulnerabilitiesPoCCVE-2026-52774: YesWiki Bazar Widget - Reflected XSS via 'id' ParameterPoCCVE-2025-14726: WordPress Widgets for Social Photo Feed <= 1.8 - Information DisclosurePoCCVE-2026-4257: WordPress Contact Form by Supsystic - Server-Side Template InjectionWordPress Contact-form-by-supsystic SSTI注入(CVE-2026-4257)PoCCVE-2024-30464: WPZOOM Social Icons Widget <= 4.2.15 - Missing AuthorizationPoCCVE-2022-44588: Cryptocurrency Widgets Pack <= 1.8.1 - SQL InjectionPoCCVE-2024-13099: Widget4Call WordPress - Cross-Site ScriptingPoCwp-cf7-data-source-fpd: WordPress Data Source for Contact Form 7 - Full Path Disclosure孚盟云CRM /m/Dingding/Ajax/AjaxBusinessPrice.ashx GetContactEmail SQL 注入漏洞PoCwp-contact-form-7-fpd: WordPress Contact Form 7 - Full Path DisclosurePoCwp-contact-form-fpd: WordPress Contact Form - Full Path DisclosurePoCwp-widget-logic-fpd: WordPress Widget Logic - Full Path Disclosure