CVE-2026-82901 - Ultra Addons for Contact Form 7 = 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field
Brief
CVE ID : CVE-2026-82901
Published : Sept. 26, 2026, 6:28 p. m.
- 32 minutes ago
Description : The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.
- 50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
