Arbitrary File Upload Vulnerability in Extensions For CF7 Plugin by WordPress
CVE-2026-94589
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-94589?
The Extensions For CF7 plugin for WordPress is susceptible to arbitrary file upload due to inadequate validation checks in its extcf7_submit function. This vulnerability arises from the lack of proper file extension, MIME type, and size validation in the signature field's validation filter. Additionally, the absence of PHP execution safeguards in the upload directory, compounded by a bypass of the sanitize_file_name() function, allows attackers to upload potentially executable files. Consequently, this security flaw can lead to remote code execution by unauthenticated users, posing significant risks to WordPress sites using this plugin.
Affected Version(s)
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) 0 <= 3.4.5