Description
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.
Published: 2026-09-26
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress-extensions
Wordpress-extensions ultra Addons For Contact Form 7
Vendors & Products Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress-extensions
Wordpress-extensions ultra Addons For Contact Form 7

Sat, 26 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.
Title Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themefic Ultimate Addons For Contact Form 7
Wordpress-extensions Ultra Addons For Contact Form 7
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-26T22:51:16.926Z

Reserved: 2026-08-31T09:23:20.843Z

Link: CVE-2026-82901

cve-icon Vulnrichment

Updated: 2026-09-26T22:48:07.108Z

cve-icon NVD

Status : Received

Published: 2026-09-26T19:16:28.427

Modified: 2026-09-26T23:16:37.000

Link: CVE-2026-82901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T11:43:15Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type