Description
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).
Published: 2025-12-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized PDF Generation
Action: Apply Update
AI Analysis

Impact

The Ultra Addons for Contact Form 7 plugin contains a missing capability check on the uacf7_get_generated_pdf function in all versions up to 3.5.33. This flaw allows any authenticated user with at least Subscriber level, when the PDF Generator and Database addons are enabled, to request and download a PDF that contains the data of any form submission. The vulnerability is classified as CWE‑639 (Authority Bypass), exposing confidential submission data without authorization. With a CVSS score of 4.3, the impact can reach moderate confidentiality loss but the exploitability is low because the attacker must be logged in and the plugin features must be activated.

Affected Systems

Affected systems are sites running the WordPress plugin Ultra Addons for Contact Form 7, themefic, in versions up to 3.5.33 inclusive. The issue only surfaces when both the PDF Generator addon and the Database addon are turned on, although they are disabled by default. The plugin is commonly deployed on contact forms, so many WordPress installations may be susceptible if they remain on or below the affected version.

Risk and Exploitability

Risk assessment indicates a CVSS score of 4.3 and an EPSS score of less than 1 %, meaning that while the confidentiality effect is moderate, the probability of exploitation in the wild is low. The vulnerability is not listed in CISA's KEV catalog. Exploitability requires user authentication and access to the PDF generation endpoint, typically easy for a legitimate subscriber to obtain. An attacker could harvest sensitive data from form submissions, potentially enabling phishing or data abuse. Advisory suggests prompt remediation, as the attack vector is simple and the data exposed can be valuable.

Generated by OpenCVE AI on April 22, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ultra Addons for Contact Form 7 to version 3.5.34 or later, which adds the missing capability check.
  • If an update is delayed, deactivate the PDF Generator and Database addons on the site to remove the vulnerable functionality.
  • Review and tighten user role capabilities so that Subscriber profiles do not have unnecessary access; consider removing the Subscriber role if it is not needed for the site.
  • Optionally, enable a web application firewall rule or custom filter to block requests to the PDF generation endpoint for non‑administrative users, ensuring only authorized users can trigger PDF creation.

Generated by OpenCVE AI on April 22, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress
Wordpress wordpress

Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 07:00:00 +0000

Type Values Removed Values Added
Description The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).
Title Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Themefic Ultimate Addons For Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:47:07.182Z

Reserved: 2025-12-09T16:40:32.811Z

Link: CVE-2025-14356

cve-icon Vulnrichment

Updated: 2025-12-12T20:30:36.763Z

cve-icon NVD

Status : Deferred

Published: 2025-12-12T07:15:44.733

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T00:30:04Z

Weaknesses