CPE
The Extensions For CF7 WordPress plugin is vulnerable to unauthenticated remote code execution via arbitrary file upload due to insufficient input validation in the extcf7_submit function.