{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ultra-addons-for-contact-form-7--3.5.50/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ultraaddons:ultra_addons_for_contact_form_7:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82901"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ultra Addons for Contact Form 7 (\u003c= 3.5.50)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Ultra Addons"],"content_html":"\u003cp\u003eThe Ultra Addons for Contact Form 7 plugin for WordPress is affected by a critical arbitrary file upload vulnerability, identified as CVE-2026-82901. The flaw resides within the 'uacf7_wpcf7_mail_components' function, which fails to adequately validate file types during upload operations. This vulnerability affects all versions of the plugin up to and including 3.5.50.\u003c/p\u003e\n\u003cp\u003eThe exploitation of this vulnerability is contingent upon the 'PDF Generator' module being enabled within the plugin settings, which is not the default configuration. When active, an unauthenticated attacker can upload malicious files, such as PHP shells, directly to the web server. Successful exploitation allows for remote code execution, granting the attacker control over the WordPress environment. Organizations using this plugin should verify if the PDF Generator module is active and update to a patched version immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-82901 enables unauthenticated remote code execution on WordPress instances. This can lead to full site compromise, data exfiltration, and the establishment of persistent backdoors. Because the plugin is a common add-on for Contact Form 7, a wide range of WordPress-based business sites are potentially at risk. The impact includes unauthorized access to site configuration, database content, and the ability to execute system-level commands with the privileges of the web server process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Ultra Addons for Contact Form 7 plugin to a version beyond 3.5.50 immediately to remediate CVE-2026-82901.\u003c/li\u003e\n\u003cli\u003eReview the configuration of the Ultra Addons plugin to ensure the PDF Generator module is disabled if it is not strictly required for business operations.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress uploads directory for unexpected files with executable extensions (e.g., .php, .php5, .phtml) created after the plugin was deployed.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at plugin-specific endpoints associated with file uploads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T21:01:01Z","date_published":"2026-09-26T21:01:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ultra-addons-rce/","summary":"An arbitrary file upload vulnerability in the Ultra Addons for Contact Form 7 plugin, tracked as CVE-2026-82901, allows unauthenticated attackers to execute arbitrary code when the PDF Generator module is enabled.","title":"Arbitrary File Upload Vulnerability in Ultra Addons for Contact Form 7","url":"https://feed.craftedsignal.io/briefs/2026-09-ultra-addons-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Ultra Addons for Contact Form 7 (\u003c= 3.5.50)","version":"https://jsonfeed.org/version/1.1"}