CRITICAL
9.8 CVE-2026-94589 Published 10 Oct 2026
WordPress Extensions For CF7 Plugin Arbitrary File Upload Vulnerability
Worried this affects your website?
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload.
Affected versions and conditions:
- All versions up to, and including, 3.4.5.
- The issue is in the extcf7_submit function, via the signature field's validation_filter().
- Missing file extension, MIME type, and size validation, plus no PHP-execution guards in the upload directory.
- A sanitize_file_name() bypass converts shell.php- into shell.php.
- Unauthenticated attackers can upload executable files, leading to remote code execution.
Reference: CVE-2026-94589 on NVD
← Back to Security News