CRITICAL 9.8 CVE-2026-82901 Published 26 Sept 2026

WordPress Ultra Addons for Contact Form 7 Arbitrary File Upload Vulnerability

Worried this affects your website?

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the uacf7_wpcf7_mail_components function.

This affects all versions up to and including 3.5.50. The issue allows unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible.

  • Affected versions: all versions up to and including 3.5.50
  • Precondition: the plugin's PDF Generator module must be enabled (disabled by default)
  • Impact: arbitrary file upload, potentially leading to remote code execution

Reference: CVE-2026-82901 on NVD

← Back to Security News