PT-2026-95755 · WordPress · Ultimate Addons For Contact Form 7

·

CVE-2026-84750

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ultra Addons for Contact Form 7 versions prior to 3.5.51
Description Unauthenticated users can upload arbitrary files because the plugin fails to validate file types or extensions in one of its form fields. Uploaded files are stored in a predictable public path with the attacker-specified extension. On systems using Debian or Ubuntu Apache packages, where the PHP handler maps .phar files to PHP, this can lead to Remote Code Execution and full site takeover. On hosts that only route .php files to the PHP handler, the uploaded script is served from the site origin, resulting in Stored Cross-Site Scripting (a vulnerability where malicious scripts are permanently stored on the target server and served to other users).
Recommendations Update Ultra Addons for Contact Form 7 to version 3.5.51 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84750

Affected Products

Ultimate Addons For Contact Form 7