PT-2026-109477 · Ht Plugins · Extensions For Cf7

·

CVE-2026-94589

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7 submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize file name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94589

Affected Products

Extensions For Cf7