<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:extensions_for_cf7_project:extensions_for_cf7:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aextensions_for_cf7_projectextensions_for_cf7wordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aextensions_for_cf7_projectextensions_for_cf7wordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in Extensions For CF7 WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94589-extensions-cf7/</link><pubDate>Sat, 10 Oct 2026 05:34:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94589-extensions-cf7/</guid><description>The Extensions For CF7 WordPress plugin is vulnerable to unauthenticated remote code execution via arbitrary file upload due to insufficient input validation in the extcf7_submit function.</description><content:encoded><![CDATA[<p>The Extensions For CF7 (Contact Form 7 Database, Conditional Fields, and Redirection) plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 3.4.5. The vulnerability resides within the extcf7_submit function, which fails to properly validate the file extension, MIME type, or size of uploaded files.</p>
<p>The exploitation is facilitated by a bypass in the sanitize_file_name() function, which allows attackers to craft filenames such as shell.php- that are converted to executable .php files. Furthermore, the absence of security guards (such as .htaccess or directory permissions) in the target upload directory allows these files to be executed by the web server. Unauthenticated attackers can exploit this flaw to achieve remote code execution (RCE) on the underlying WordPress environment, leading to full site compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the web server. This can lead to complete site takeover, unauthorized data access, exfiltration of sensitive information, or the use of the server as a pivot point for further network compromise. The scope of impact includes any WordPress site running the affected plugin versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Extensions For CF7 plugin to the latest version immediately.</li>
<li>Audit the web server logs and the plugin's upload directory for any suspicious files uploaded via the extcf7_submit function.</li>
<li>Implement strict file execution restrictions in web server configurations (Nginx/Apache) for all plugin upload directories to prevent execution of PHP files in non-authorized locations.</li>
<li>Enable monitoring for abnormal HTTP POST requests directed at the plugin endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>arbitrary-file-upload</category><category>rce</category><category>web-application</category></item></channel></rss>