{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/extensions-for-cf7--3.4.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:extensions_for_cf7_project:extensions_for_cf7:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-94589"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Extensions For CF7 (\u003c= 3.4.5)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","arbitrary-file-upload","rce","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Extensions For CF7 (Contact Form 7 Database, Conditional Fields, and Redirection) plugin for WordPress is vulnerable to an arbitrary file upload flaw affecting all versions up to and including 3.4.5. The vulnerability resides within the extcf7_submit function, which fails to properly validate the file extension, MIME type, or size of uploaded files.\u003c/p\u003e\n\u003cp\u003eThe exploitation is facilitated by a bypass in the sanitize_file_name() function, which allows attackers to craft filenames such as shell.php- that are converted to executable .php files. Furthermore, the absence of security guards (such as .htaccess or directory permissions) in the target upload directory allows these files to be executed by the web server. Unauthenticated attackers can exploit this flaw to achieve remote code execution (RCE) on the underlying WordPress environment, leading to full site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the web server. This can lead to complete site takeover, unauthorized data access, exfiltration of sensitive information, or the use of the server as a pivot point for further network compromise. The scope of impact includes any WordPress site running the affected plugin versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Extensions For CF7 plugin to the latest version immediately.\u003c/li\u003e\n\u003cli\u003eAudit the web server logs and the plugin's upload directory for any suspicious files uploaded via the extcf7_submit function.\u003c/li\u003e\n\u003cli\u003eImplement strict file execution restrictions in web server configurations (Nginx/Apache) for all plugin upload directories to prevent execution of PHP files in non-authorized locations.\u003c/li\u003e\n\u003cli\u003eEnable monitoring for abnormal HTTP POST requests directed at the plugin endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:34:00Z","date_published":"2026-10-10T05:34:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94589-extensions-cf7/","summary":"The Extensions For CF7 WordPress plugin is vulnerable to unauthenticated remote code execution via arbitrary file upload due to insufficient input validation in the extcf7_submit function.","title":"Unauthenticated Remote Code Execution in Extensions For CF7 WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94589-extensions-cf7/"}],"language":"en","title":"CraftedSignal Threat Feed - Extensions for CF7 (\u003c= 3.4.5)","version":"https://jsonfeed.org/version/1.1"}