Impact
The Generate PDF using Contact Form 7 WordPress plugin version 4.2.2 and earlier allows an attacker to send a specially crafted form containing an array-valued field that directs the plugin to fetch an image without validating the destination. The plugin’s PDF renderer then includes the fetched content in the generated PDF, enabling the attacker to read the response of internal resources. This behavior leaks sensitive internal data and can be used for further reconnaissance or exploitation, thereby compromising confidentiality and potentially availability of the affected server.
Affected Systems
WordPress sites that have the Generate PDF using Contact Form 7 plugin installed in a version earlier than 4.2.2. No other specific vendor or product versions are identified beyond the plugin itself.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity, while the EPSS score of less than 1% suggests that the probability of exploitation is low at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated access to the plugin’s form endpoint, where an attacker submits a malicious array-valued field to trigger the server‑side request. If successful, the attacker receives a PDF containing the internal response, potentially exposing files or services that should remain private.
OpenCVE Enrichment