Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themefic
Themefic ultimate Addons For Contact Form 7 Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themefic
Themefic ultimate Addons For Contact Form 7 Wordpress Wordpress wordpress |
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default). | |
| Title | Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-12T20:30:42.366Z
Reserved: 2025-12-09T16:40:32.811Z
Link: CVE-2025-14356
Updated: 2025-12-12T20:30:36.763Z
Status : Awaiting Analysis
Published: 2025-12-12T07:15:44.733
Modified: 2025-12-12T15:17:31.973
Link: CVE-2025-14356
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:17:07Z