Extensions For CF7 <= 3.4.5 - Unauthenticated Limited Arbitrary File Upload via Signature Field
- ID
- WPSEC-2026-0469
- Plugin
- Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) (extensions-for-cf7)
- Affected
- from 3.2.7 before 3.4.6
- Remediation
- Update to 3.4.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-434
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- Extensions For CF7 on WPSec AttackSurface
- Fix released
- Published
Description
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to limited arbitrary file uploads in versions 3.2.7 up to, and including, 3.4.5. This is due to the Signature form field accepting an uploaded file without validating its type, and the plugin's form submission storage copying every uploaded file into the publicly accessible wp-content/uploads/extcf7_uploads directory, which had no protection against script execution, under a predictable name built from the submission time, the field name and the client-supplied file name. Contact Form 7 renames files with extensions such as .php or .phtml, but other types such as .phar, .html or .svg are stored as uploaded. This makes it possible for unauthenticated attackers to upload files that may make remote code execution possible on servers configured to execute .phar files, or that lead to stored cross-site scripting through HTML or SVG content. Exploitation requires a form that contains the plugin's Signature field and a submission whose notification email is sent successfully.
References
- https://wpsec.com/vuln/WPSEC-2026-0469/
- https://plugins.svn.wordpress.org/extensions-for-cf7/tags/3.4.6/
- https://wordpress.org/plugins/extensions-for-cf7/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS