PT-2026-99421 · WordPress · Ultimate Addons For Contact Form 7
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ultra Addons for Contact Form 7 versions prior to 3.5.51
Description
Insufficient file type validation in the
uacf7 wpcf7 mail components() function allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. This issue is only exploitable if the PDF Generator module is enabled, as it is disabled by default.Recommendations
Update the plugin to a version newer than 3.5.50.
As a temporary mitigation, ensure the PDF Generator module remains disabled.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ultimate Addons For Contact Form 7