PT-2026-109477 · Ht Plugins · Extensions For Cf7

·

CVE-2026-94589

·

Publicado

2026-10-10

·

Atualizado

2026-10-10

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7 submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize file name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-94589

Produtos afetados

Extensions For Cf7