Description
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

The Extensions For CF7 plugin for WordPress allows an attacker to upload arbitrary files through the signature field because the file extension, MIME type, and size are not validated, and the sanitization routine can be bypassed by using a filename such as shell.php-. The upload directory does not enforce PHP execution guards, so an attacker can place executable scripts and trigger remote code execution. This flaw is fully exploitable by unauthenticated users via the extcf7_submit function, giving them full control over the vulnerable host.

Affected Systems

WordPress sites running the Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin version 3.4.5 or older. The plugin is distributed by htplugins. Any deployment that has not upgraded past version 3.4.5 is affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating critical severity. No EPSS score is available, but the flaw is a classic arbitrary file upload that is easy to detect and exploit. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw simply by sending an HTTP request to the CF7 submission endpoint without authentication, uploading a crafted file that the server will execute. Because the upload directory lacks PHP execution protection, the risk of remote code execution is immediate if the site is accessible over the network.

Generated by OpenCVE AI on October 10, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Extensions For CF7 to version 3.4.6 or later to remove the unvalidated upload path.
  • If an upgrade cannot be performed right away, disable the signature field or the entire plugin to block the upload functionality.
  • Configure the wp-content/uploads directory to disallow PHP execution by setting appropriate file permissions or adding a .htaccess rule that blocks .php and other executable extensions.

Generated by OpenCVE AI on October 10, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Title Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T03:26:46.082Z

Reserved: 2026-09-21T20:57:21.736Z

Link: CVE-2026-94589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T04:18:19.713

Modified: 2026-10-10T04:18:19.713

Link: CVE-2026-94589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T04:30:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type