PT-2026-99421 · WordPress · Ultimate Addons For Contact Form 7

·

CVE-2026-82901

·

Published

2026-09-26

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ultra Addons for Contact Form 7 versions prior to 3.5.51
Description Insufficient file type validation in the uacf7 wpcf7 mail components() function allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. This issue is only exploitable if the PDF Generator module is enabled, as it is disabled by default.
Recommendations Update the plugin to a version newer than 3.5.50. As a temporary mitigation, ensure the PDF Generator module remains disabled.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82901

Affected Products

Ultimate Addons For Contact Form 7