CVE-2025-8141 describes an arbitrary file deletion vulnerability in the Redirection for Contact Form 7 plugin for WordPress, affecting all versions up to and including 3.2.4. This critical flaw stems from insufficient file path validation, allowing unauthenticated attackers to delete arbitrary files on the server. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, potentially leading to remote code execution by deleting critical files like wp-config.php. There is currently no public exploit intelligence, such as Metasploit or Nuclei modules, and the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themeisle | Redirection For Contact Form 7 | >= 0, <= 3.2.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.