Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload
CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51 or newer.
Ultra Addons for Contact Form 7 versions 3.5.50 and earlier contain a critical unauthenticated arbitrary file upload vulnerability tracked as CVE-2026-82901. The issue can allow a remote attacker to upload a dangerous file and, depending on server configuration and upload location, potentially achieve remote code execution.
The vulnerability was disclosed by Wordfence and carries a CVSS score of 9.8 (Critical). It is exploitable only when the plugin’s PDF Generator module is enabled. That module is disabled by default, but sites that use it should treat this as an urgent update.
Vulnerability summary
| Product | Ultra Addons for Contact Form 7 |
|---|---|
| Plugin slug | ultimate-addons-for-contact-form-7 |
| CVE | CVE-2026-82901 |
| Severity | Critical, CVSS 9.8 |
| Affected versions | All versions up to and including 3.5.50 |
| Fixed version | 3.5.51 |
| Current version at publication | 3.5.52 |
| Authentication required | None |
| Required configuration | PDF Generator module enabled |
| Potential impact | Arbitrary file upload and possible remote code execution |
How CVE-2026-82901 works
The affected code handles files associated with the signature form field while preparing Contact Form 7 mail components through the uacf7_wpcf7_mail_components flow. In vulnerable versions, the upload path does not adequately restrict the file type. An unauthenticated visitor who can submit an affected form may therefore be able to place a server-executable file on the site.
This is a configuration-dependent vulnerability: the PDF Generator module must be active. Administrators should not assume they are safe simply because they do not intentionally use signature fields. Confirm the module state and plugin version directly.
Immediate remediation
- Update Ultra Addons for Contact Form 7 to version 3.5.51 or newer. The current WordPress.org release is 3.5.52.
- If the update cannot be completed immediately, disable the PDF Generator module until the plugin is patched.
- Purge page, object, CDN, and reverse-proxy caches after updating.
- Review recent uploads and web-server request logs for suspicious form submissions or executable files.
- If compromise is suspected, rotate WordPress administrator, hosting, database, SFTP, and API credentials after cleaning the site.
Verify and update with WP-CLI
Check the installed version:
wp plugin get ultimate-addons-for-contact-form-7 --field=version
Install the latest available update:
wp plugin update ultimate-addons-for-contact-form-7
Then confirm that the installed version is at least 3.5.51:
wp plugin get ultimate-addons-for-contact-form-7 --fields=name,status,version,update
Check for signs of compromise
Search the uploads directory for executable extensions that normally should not be present there:
find wp-content/uploads -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.phar' \) -print
Any result requires investigation; do not delete a file solely because it matches the command. Record its path, timestamps, owner, hash, and related access-log entries first.
Continue with these defensive checks:
wp core verify-checksums
wp plugin verify-checksums ultimate-addons-for-contact-form-7
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp plugin list --status=must-use
wp cron event list
Review access logs for unusual POST requests to pages containing Contact Form 7 forms, especially forms using PDF or signature functionality. Also look for newly created administrator accounts, unfamiliar must-use plugins, modified theme files, unexpected scheduled tasks, and PHP files beneath wp-content/uploads.
If the site may already be compromised
Updating closes the vulnerable code path but does not remove files or accounts already created by an attacker. Take the site out of service if necessary, preserve logs, compare WordPress core and plugin files with clean packages, replace affected software from trusted sources, remove unauthorized persistence, and rotate secrets. Restore from a known-clean backup only after identifying the initial access path so the vulnerable configuration is not reintroduced.
Sources
- Wordfence Intelligence vulnerability record
- Official WordPress.org plugin page and changelog
- CVE-2026-82901 record
WPDeeply did not discover this vulnerability. This advisory summarizes the public disclosure and provides defensive remediation guidance.