Impact
The Extensions For CF7 plugin for WordPress allows an attacker to upload arbitrary files through the signature field because the file extension, MIME type, and size are not validated, and the sanitization routine can be bypassed by using a filename such as shell.php-. The upload directory does not enforce PHP execution guards, so an attacker can place executable scripts and trigger remote code execution. This flaw is fully exploitable by unauthenticated users via the extcf7_submit function, giving them full control over the vulnerable host.
Affected Systems
WordPress sites running the Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin version 3.4.5 or older. The plugin is distributed by htplugins. Any deployment that has not upgraded past version 3.4.5 is affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. No EPSS score is available, but the flaw is a classic arbitrary file upload that is easy to detect and exploit. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw simply by sending an HTTP request to the CF7 submission endpoint without authentication, uploading a crafted file that the server will execute. Because the upload directory lacks PHP execution protection, the risk of remote code execution is immediate if the site is accessible over the network.
OpenCVE Enrichment