Skip to content
Threat Feed
critical advisory

Unauthenticated Remote Code Execution in Extensions For CF7 WordPress Plugin

The Extensions For CF7 WordPress plugin is vulnerable to unauthenticated remote code execution via arbitrary file upload due to insufficient input validation in the extcf7_submit function.

CVE search metadata

CVE search record: CVE-2026-94589. Severity: critical. CVSS: 9.8. KEV: no. Product: Extensions For CF7 (<= 3.4.5). Brief: Unauthenticated Remote Code Execution in Extensions For CF7 WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94589-extensions-cf7/

The Extensions For CF7 (Contact Form 7 Database, Conditional Fields, and Redirection) plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 3.4.5. The vulnerability resides within the extcf7_submit function, which fails to properly validate the file extension, MIME type, or size of uploaded files.

The exploitation is facilitated by a bypass in the sanitize_file_name() function, which allows attackers to craft filenames such as shell.php- that are converted to executable .php files. Furthermore, the absence of security guards (such as .htaccess or directory permissions) in the target upload directory allows these files to be executed by the web server. Unauthenticated attackers can exploit this flaw to achieve remote code execution (RCE) on the underlying WordPress environment, leading to full site compromise.

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the web server. This can lead to complete site takeover, unauthorized data access, exfiltration of sensitive information, or the use of the server as a pivot point for further network compromise. The scope of impact includes any WordPress site running the affected plugin versions.

Recommendation

  • Update the Extensions For CF7 plugin to the latest version immediately.
  • Audit the web server logs and the plugin's upload directory for any suspicious files uploaded via the extcf7_submit function.
  • Implement strict file execution restrictions in web server configurations (Nginx/Apache) for all plugin upload directories to prevent execution of PHP files in non-authorized locations.
  • Enable monitoring for abnormal HTTP POST requests directed at the plugin endpoint.

Immediate actions

Patch Extensions For CF7 plugin to the latest version

IT Operations 24h

Threat Hunt

Search web logs for POST requests to extcf7_submit containing suspicious filename patterns ending in .php

T1203 high high confidence hunt now

Data: Web server access logs

Mitigations

Disable the plugin if patching is not immediately feasible

immediate IT Operations

CVE-2026-94589

Detection coverage 1

Detect CVE-2026-94589 Exploitation - Unauthorized File Upload to CF7 Plugin

critical

Detects potential exploitation attempts of CVE-2026-94589 by monitoring for POST requests to the extcf7_submit function containing filename patterns typical of RCE bypasses.

sigma tactics: execution, initial_access techniques: T1190, T1203 sources: webserver

Detection queries are available on the platform. Get full rules →