CVE-2026-94589
Received Received - Intake

Arbitrary File Upload in Extensions For CF7 WordPress Plugin

Vulnerability report for CVE-2026-94589, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
htplugins Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Extensions For CF7 WordPress plugin versions up to 3.4.5. It allows unauthenticated attackers to upload malicious files through a function called extcf7_submit. The plugin fails to properly check file types, sizes, or MIME types in the signature field. Attackers can bypass restrictions and upload executable files like PHP scripts, leading to remote code execution on the server.

Detection Guidance

Check WordPress installations for the Extensions For CF7 plugin versions up to 3.4.5. Look for unexpected files in upload directories, especially those with PHP extensions or unusual names like shell.php-. Inspect web server logs for POST requests to the extcf7_submit function.

Impact Analysis

If you use this plugin, an attacker could upload a malicious file to your WordPress site. This could allow them to take control of your website, steal data, or use it to attack other systems. The high CVSS score (9.8) indicates severe impact, including full system compromise.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR (if personal data is exposed) or HIPAA (if protected health information is compromised). Organizations using this plugin may face legal penalties, fines, or reputational damage due to non-compliance with these regulations.

Mitigation Strategies

Immediately update the Extensions For CF7 plugin to the latest version. Remove the plugin if unused. Restrict file upload permissions and ensure upload directories do not allow PHP execution. Monitor for unauthorized file uploads or suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94589. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart