CVE-2026-82901 Overview
The Ultra Addons for Contact Form 7 plugin for WordPress contains an arbitrary file upload vulnerability in the uacf7_wpcf7_mail_components function. The flaw stems from insufficient file type validation and affects all versions up to and including 3.5.50. Unauthenticated attackers can upload arbitrary files to the affected site's server, which may lead to remote code execution. Exploitation requires the plugin's PDF Generator module to be enabled, which is not the default configuration. The vulnerability is classified under CWE-434: Unrestricted Upload of File with Dangerous Type.
Critical Impact
Unauthenticated remote attackers can upload arbitrary files and achieve remote code execution on WordPress sites running the vulnerable plugin with the PDF Generator module enabled.
Affected Products
- Ultra Addons for Contact Form 7 plugin for WordPress — all versions up to and including 3.5.50
- WordPress sites with the plugin's PDF Generator module enabled
- Sites running the vulnerable uacf7_wpcf7_mail_components function path
Discovery Timeline
- 2026-09-26 - CVE-2026-82901 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-82901
Vulnerability Analysis
The vulnerability resides in the uacf7_wpcf7_mail_components function within the Ultra Addons for Contact Form 7 plugin. The function processes mail components related to the PDF Generator addon but fails to validate uploaded file types against an allowlist. An unauthenticated attacker can submit a crafted request containing a PHP or other executable file disguised as an expected upload. The server writes the file to a web-accessible location, enabling the attacker to request the file directly and trigger code execution. Because the plugin runs within the WordPress process, successful exploitation yields code execution under the web server user account.
Root Cause
The root cause is missing or insufficient MIME type and extension validation in the file handling path tied to the PDF Generator module. The vulnerable logic appears in addons/pdf-generator/pdf-generator.php around lines 608 and 807, as referenced in the plugin source for tag 3.5.48. The fix is tracked in plugin changeset 3698232.
Attack Vector
Exploitation occurs over the network without authentication or user interaction. An attacker sends a crafted HTTP POST request to the vulnerable Contact Form 7 submission endpoint on a site where the PDF Generator module is enabled. The payload includes a file field with a server-side executable such as a PHP web shell. Once uploaded, the attacker navigates to the file path and executes commands in the context of the web server. Additional context is available in the Wordfence vulnerability report.
Detection Methods for CVE-2026-82901
Indicators of Compromise
- Unexpected .php, .phtml, or .phar files in WordPress wp-content/uploads/ subdirectories associated with the plugin
- POST requests to Contact Form 7 submission endpoints containing multipart file uploads with executable extensions
- Outbound connections or reverse shells originating from the PHP-FPM or Apache worker process shortly after a form submission
- New or modified administrator accounts created outside normal workflows
Detection Strategies
- Audit the wp-content/uploads/ and PDF Generator working directories for files with executable extensions or mismatched MIME types
- Enable WordPress file integrity monitoring to detect new PHP files created under upload paths
- Inspect web server access logs for POST requests to Contact Form 7 endpoints followed by direct GET requests to newly created files
Monitoring Recommendations
- Monitor web application firewall logs for multipart requests containing dangerous file extensions targeting plugin endpoints
- Alert on PHP process execution originating from files inside wp-content/uploads/
- Track plugin version inventory across all WordPress sites and flag installations at or below version 3.5.50
How to Mitigate CVE-2026-82901
Immediate Actions Required
- Update the Ultra Addons for Contact Form 7 plugin to the patched version released in changeset 3698232
- Disable the PDF Generator module until the update is applied
- Review wp-content/uploads/ for unauthorized files and remove any confirmed web shells
- Rotate WordPress administrator credentials and API keys if compromise is suspected
Patch Information
The vendor addressed the vulnerability in the plugin release that follows version 3.5.50. The fix is published in WordPress plugin changeset 3698232 for the ultimate-addons-for-contact-form-7 repository. Site operators should apply the update through the WordPress plugin management interface or via WP-CLI.
Workarounds
- Disable the PDF Generator module in the plugin settings, which removes the vulnerable code path from execution
- Deactivate the Ultra Addons for Contact Form 7 plugin entirely if the PDF Generator feature is not required
- Deploy a web application firewall rule blocking multipart uploads with executable file extensions to Contact Form 7 endpoints
# Update plugin via WP-CLI
wp plugin update ultimate-addons-for-contact-form-7
# Verify installed version is above 3.5.50
wp plugin get ultimate-addons-for-contact-form-7 --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
