CVE-2025-7360
Published
CVSS v3
9.1
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT
Description
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).
<p><strong>Stop struggling with complicated form plugins.</strong> HT Contact Form is the WordPress form builder that gets out of your way and lets you create beautiful, functional forms in minutes – not hours.</p>
<p>Whether you need a simple contact form, a detailed application, or a complex survey with conditional logic, HT Contact Form has you covered. <strong>No coding required. No expensive add-ons. Just drag, drop, and publish.</strong></p>
<p><strong><a href="https://hasthemes.com/plugins/ht-contact-form/" rel="nofollow ugc">Learn More</a></strong> | <strong><a href="https://hasthemes.com/docs-category/ht-contact-forms/" rel="nofollow ugc">Documentation</a></strong> | <strong><a href="https://hasthemes.com/contact-us/" rel="nofollow ugc">Support</a></strong></p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/raW1OPdg46Q?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<h3>Key Features</h3>
<p>🎨 <strong>Drag & Drop Builder</strong> – Design forms visually with our intuitive builder. No coding needed.</p>
<p>📝 <strong>38+ Form Fields</strong> – Everything from basic text inputs to signatures, file uploads, and repeater fields.</p>
<p>🔗 <strong>21+ Integrations</strong> – Connect to Mailchimp, HubSpot, Zapier, Slack, and more – all included free.</p>
<p>💾 <strong>Save & Resume</strong> – Let users save their progress and complete forms later via unique link.</p>
<p>🔀 <strong>Conditional Logic</strong> – Show or hide fields based on user selections.</p>
<p>🛡️ <strong>Spam Protection</strong> – Built-in honeypot, reCAPTCHA v2/v3, and hCaptcha support.</p>
<p>📊 <strong>Entry Management</strong> – Store, search, filter, and export all submissions from your dashboard.</p>
<p>📧 <strong>Email Notifications</strong> – Instant alerts with 5 pre-designed email templates.</p>
<p>🏷️ <strong>Smart Tags</strong> – Dynamic field values that auto-populate from user data, URLs, or other fields.</p>
<p>📱 <strong>Fully Responsive</strong> – Forms look perfect on desktop, tablet, and mobile.</p>
<p>🎯 <strong>Form Styling</strong> – Customize colors, fonts, borders, and spacing to match your brand.</p>
<p>📤 <strong>Export Options</strong> – Download entries as CSV, Excel, ODS, or JSON.</p>
<h3>What’s New</h3>
<p>🔗 <strong>9 New Integrations</strong> – Connect forms to GetResponse, Drip, Moosend, iContact, MailPoet, Notion, Trello, HubSpot, and Zoho CRM.</p>
<p>📧 <strong>Email Marketing</strong> – GetResponse, Drip, Moosend, iContact, and MailPoet integrations for subscriber management.</p>
<p>💼 <strong>CRM Integrations</strong> – HubSpot and Zoho CRM for contact and lead management.</p>
<p>📂 <strong>Productivity Tools</strong> – Notion databases and Trello boards integration for workflow automation.</p>
<h3>Build Any Form You Need</h3>
<ul>
<li>📬 <strong>Contact Forms</strong> – Simple inquiry forms with name, email, and message</li>
<li>🎯 <strong>Lead Generation</strong> – Capture leads with custom fields and send to your CRM</li>
<li>📋 <strong>Surveys & Feedback</strong> – Multi-question forms with ratings, NPS, and conditional logic</li>
<li>✅ <strong>Signup Forms</strong> – Collect user details for newsletters, events, or services</li>
<li>📄 <strong>Application Forms</strong> – Long forms with save & resume functionality</li>
<li>🎫 <strong>Support Requests</strong> – Ticket creation with file attachments and priority selection</li>
</ul>
<h3>38+ Form Fields</h3>
<p>✏️ <strong>Basic Input</strong><br />
Text, Textarea, Email, Number, Phone, Password, Website, Name (with formats)</p>
<p>☑️ <strong>Selection</strong><br />
Dropdown, Radio Buttons, Checkboxes, Multiple Choice, Country List</p>
<p>⚙️ <strong>Advanced</strong><br />
Repeater (dynamic rows), Chained Select, Post Selection, Rich Text Editor</p>
<p>📅 <strong>Date & Time</strong><br />
Date/Time Picker (with calendar and time selection)</p>
<p>📎 <strong>Uploads</strong><br />
File Upload, Image Upload, Signature Capture</p>
<p>🧩 <strong>Layout</strong><br />
Section Break, Custom HTML, Shortcode Embed</p>
<p>🔐 <strong>Security</strong><br />
reCAPTCHA (v2 & v3), hCaptcha, GDPR Consent, Terms & Conditions</p>
<p>⭐ <strong>Special</strong><br />
Save & Resume, Star Rating, NPS Score, Color Picker, Range Slider, Mask Input, Hidden Field, Action Hook</p>
<h3>21+ Integrations</h3>
<p>📧 <strong>Email Marketing</strong><br />
Mailchimp, ActiveCampaign, MailerLite, GetResponse, Drip, Moosend, iContact, MailPoet, Constant Contact, Brevo</p>
<p>💼 <strong>CRM</strong><br />
HubSpot, Zoho CRM, Insightly, OnepageCRM</p>
<p>📂 <strong>Productivity</strong><br />
Notion, Trello, Slack, Discord</p>
<p>⚡ <strong>Automation</strong><br />
Zapier (connect to 5000+ apps), Custom Webhooks</p>
<p>🎫 <strong>Support</strong><br />
Support Genix (helpdesk tickets)</p>
<h3>Why Choose HT Contact Form?</h3>
<p>💰 <strong>Free & Powerful</strong> – Get features that competitors charge hundreds for. No form limits, no entry limits, no hidden costs.</p>
<p>⚡ <strong>Modern Interface</strong> – Built with React for a fast, smooth admin experience. No page reloads, instant previews.</p>
<p>🔗 <strong>All Integrations Included</strong> – 21+ integrations at no extra cost. Connect your forms to the tools you already use.</p>
<p>👨💻 <strong>Developer Friendly</strong> – Action hooks, custom HTML fields, and webhook support for unlimited extensibility.</p>
<p>🚀 <strong>Active Development</strong> – Regular updates with new fields, integrations, and features based on user feedback.</p>
<h3>Other Projects</h3>
<p><strong><a href="https://wordpress.org/plugins/woolentor-addons/" rel="ugc">ShopLentor (Woolentor)</a></strong> – WooCommerce page builder with 125+ widgets, 36 modules including Shopify-style checkout, Quick View, Wishlist, and Compare features.</p>
<p><strong><a href="https://wordpress.org/plugins/support-genix-lite/" rel="ugc">Support Genix</a></strong> – AI-powered helpdesk with ticketing system, knowledge base, and 24/7 chatbot support for customer service.</p>
<p><strong><a href="https://wordpress.org/plugins/ht-mega-for-elementor/" rel="ugc">HT Mega For Elementor</a></strong> – Elementor addon with 135+ widgets, AI Content Writer, Theme Builder, Mega Menu Builder, and 790+ ready blocks.</p>
<p><strong><a href="https://wordpress.org/plugins/hashbar-wp-notification-bar/" rel="ugc">Hashbar WP Notification Bar</a></strong> – Create unlimited notification bars for announcements, promotions, and alerts.</p>
<p><strong><a href="https://wordpress.org/plugins/ht-easy-google-analytics/" rel="ugc">HT Easy GA4</a></strong> – Track your website visitors and view Google Analytics dashboard reports from your website.</p>
<p><a href="https://wordpress.org/plugins/wp-plugin-manager/" rel="ugc"><strong>WP Plugin Manager</strong></a> – Disable certain plugins on specific pages or posts for better performance. Activate or deactivate plugins on a per-page basis.</p>
<p><a href="https://wordpress.org/plugins/extensions-for-cf7/" rel="ugc"><strong>Extensions For CF7</strong></a> – Contact Form 7 Database, Conditional Fields, and Mailchimp integration for lead generation.</p>
<p><a href="https://wordpress.org/plugins/whols/" rel="ugc"><strong>Whols</strong></a> – WooCommerce wholesale pricing plugin. Set wholesale prices, custom registration fields, and minimum requirements. Works like Wholesale Suite, B2Bking.</p>
<p><a href="https://wordpress.org/plugins/just-tables/" rel="ugc"><strong>JustTables</strong></a> – WooCommerce product table plugin with 28 pre-built columns, custom fields support, and drag-and-drop ordering.</p>
<p><a href="https://wordpress.org/plugins/swatchly/" rel="ugc"><strong>Swatchly</strong></a> – WooCommerce product variation swatches with color, label, and image swatch types.</p>
<p><a href="https://wordpress.org/plugins/ht-slider-for-elementor/" rel="ugc"><strong>HT Slider For Elementor</strong></a> – Powerful slider addon for Elementor with custom styling options and navigation controls.</p>
<h3>🎬 Video created by the community</h3>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/m0dwUPKQAUE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<h3>Need Help?</h3>
<p>Have a feature request or need assistance?<br />
<strong><a href="https://hasthemes.com/contact-us/" rel="nofollow ugc">Contact Us</a></strong></p>