CRITICAL 9.8 CVE-2026-94589 Published 10 Oct 2026

WordPress Extensions For CF7 Plugin Arbitrary File Upload Vulnerability

Worried this affects your website?

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload.

Affected versions and conditions:

  • All versions up to, and including, 3.4.5.
  • The issue is in the extcf7_submit function, via the signature field's validation_filter().
  • Missing file extension, MIME type, and size validation, plus no PHP-execution guards in the upload directory.
  • A sanitize_file_name() bypass converts shell.php- into shell.php.
  • Unauthenticated attackers can upload executable files, leading to remote code execution.

Reference: CVE-2026-94589 on NVD

← Back to Security News