WPDeeply
Download free plugin
Plugin Security

Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload

CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51 or newer.

Ultra Addons for Contact Form 7 arbitrary file upload vulnerability advisory

Ultra Addons for Contact Form 7 versions 3.5.50 and earlier contain a critical unauthenticated arbitrary file upload vulnerability tracked as CVE-2026-82901. The issue can allow a remote attacker to upload a dangerous file and, depending on server configuration and upload location, potentially achieve remote code execution.

The vulnerability was disclosed by Wordfence and carries a CVSS score of 9.8 (Critical). It is exploitable only when the plugin’s PDF Generator module is enabled. That module is disabled by default, but sites that use it should treat this as an urgent update.

Vulnerability summary

Product Ultra Addons for Contact Form 7
Plugin slug ultimate-addons-for-contact-form-7
CVE CVE-2026-82901
Severity Critical, CVSS 9.8
Affected versions All versions up to and including 3.5.50
Fixed version 3.5.51
Current version at publication 3.5.52
Authentication required None
Required configuration PDF Generator module enabled
Potential impact Arbitrary file upload and possible remote code execution

How CVE-2026-82901 works

The affected code handles files associated with the signature form field while preparing Contact Form 7 mail components through the uacf7_wpcf7_mail_components flow. In vulnerable versions, the upload path does not adequately restrict the file type. An unauthenticated visitor who can submit an affected form may therefore be able to place a server-executable file on the site.

This is a configuration-dependent vulnerability: the PDF Generator module must be active. Administrators should not assume they are safe simply because they do not intentionally use signature fields. Confirm the module state and plugin version directly.

Immediate remediation

  1. Update Ultra Addons for Contact Form 7 to version 3.5.51 or newer. The current WordPress.org release is 3.5.52.
  2. If the update cannot be completed immediately, disable the PDF Generator module until the plugin is patched.
  3. Purge page, object, CDN, and reverse-proxy caches after updating.
  4. Review recent uploads and web-server request logs for suspicious form submissions or executable files.
  5. If compromise is suspected, rotate WordPress administrator, hosting, database, SFTP, and API credentials after cleaning the site.

Verify and update with WP-CLI

Check the installed version:

wp plugin get ultimate-addons-for-contact-form-7 --field=version

Install the latest available update:

wp plugin update ultimate-addons-for-contact-form-7

Then confirm that the installed version is at least 3.5.51:

wp plugin get ultimate-addons-for-contact-form-7 --fields=name,status,version,update

Check for signs of compromise

Search the uploads directory for executable extensions that normally should not be present there:

find wp-content/uploads -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.phar' \) -print

Any result requires investigation; do not delete a file solely because it matches the command. Record its path, timestamps, owner, hash, and related access-log entries first.

Continue with these defensive checks:

wp core verify-checksums
wp plugin verify-checksums ultimate-addons-for-contact-form-7
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp plugin list --status=must-use
wp cron event list

Review access logs for unusual POST requests to pages containing Contact Form 7 forms, especially forms using PDF or signature functionality. Also look for newly created administrator accounts, unfamiliar must-use plugins, modified theme files, unexpected scheduled tasks, and PHP files beneath wp-content/uploads.

If the site may already be compromised

Updating closes the vulnerable code path but does not remove files or accounts already created by an attacker. Take the site out of service if necessary, preserve logs, compare WordPress core and plugin files with clean packages, replace affected software from trusted sources, remove unauthorized persistence, and rotate secrets. Restore from a known-clean backup only after identifying the initial access path so the vulnerable configuration is not reintroduced.

Sources

WPDeeply did not discover this vulnerability. This advisory summarizes the public disclosure and provides defensive remediation guidance.

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.