CVE-2025-24695: Hasthemes Extensions For CF7

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Server Side Request Forgery.This issue affects Extensions For CF7: from n/a through <= 3.2.0.

Affected products

  • Hasthemes Extensions For CF7: before 3.2.1 (fixed in 3.2.1)

Published 2025-01-24. Last modified 2026-06-17.