CVE-2026-82901
Received Received - Intake

Arbitrary File Upload in Ultra Addons for Contact Form 7

Vulnerability report for CVE-2026-82901, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: Wordfence

Description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-28
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ultra_addons contact_form_7 to 3.5.50 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Upload issue in the Ultra Addons for Contact Form 7 WordPress plugin. It exists due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function. Unauthenticated attackers can exploit this to upload arbitrary files on the server, potentially leading to remote code execution. Exploitation requires the plugin's PDF Generator module to be enabled, which is disabled by default.

Detection Guidance

To detect this vulnerability, check if the Ultra Addons for Contact Form 7 plugin is installed and enabled on your WordPress site. Verify if the PDF Generator module is active. Inspect server logs for unusual file uploads or suspicious activity in the uploads directory.

Impact Analysis

This vulnerability can allow attackers to upload malicious files to your server, which may lead to remote code execution. This could result in complete control over your website, data theft, or further attacks against your server or users. If you use the affected plugin, an attacker could exploit this without authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA compliance. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach could result in legal penalties, fines, and reputational damage due to non-compliance.

Mitigation Strategies

Immediately update the Ultra Addons for Contact Form 7 plugin to the latest version. Disable the PDF Generator module if enabled. Remove any unauthorized files uploaded to the server. Consider disabling file uploads temporarily until the plugin is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82901. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart