← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 26, 2026 · 18:28via CVEFeed

CVE-2026-82901 - Ultra Addons for Contact Form 7 = 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field

Brief

CVE ID : CVE-2026-82901

Published : Sept. 26, 2026, 6:28 p. m.

  • 32 minutes ago

Description : The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.

  • 50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→