Arbitrary File Upload Vulnerability in Extensions For CF7 Plugin by WordPress
CVE-2026-94589

9.8CRITICAL

What is CVE-2026-94589?

The Extensions For CF7 plugin for WordPress is susceptible to arbitrary file upload due to inadequate validation checks in its extcf7_submit function. This vulnerability arises from the lack of proper file extension, MIME type, and size validation in the signature field's validation filter. Additionally, the absence of PHP execution safeguards in the upload directory, compounded by a bypass of the sanitize_file_name() function, allows attackers to upload potentially executable files. Consequently, this security flaw can lead to remote code execution by unauthenticated users, posing significant risks to WordPress sites using this plugin.

Affected Version(s)

Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) 0 <= 3.4.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osman Hussein
.