# Extensions For CF7 <= 3.4.5 - Unauthenticated Limited Arbitrary File Upload via Signature Field

- **ID:** WPSEC-2026-0469
- **Plugin:** Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) (`extensions-for-cf7`), https://wordpress.org/plugins/extensions-for-cf7/
- **Affected versions:** from 3.2.7 before 3.4.6
- **Fixed in:** 3.4.6 (Update to 3.4.6 or later.)
- **Severity:** High 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-434
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/extensions-for-cf7
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0469/

## Description

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to limited arbitrary file uploads in versions 3.2.7 up to, and including, 3.4.5. This is due to the Signature form field accepting an uploaded file without validating its type, and the plugin's form submission storage copying every uploaded file into the publicly accessible wp-content/uploads/extcf7_uploads directory, which had no protection against script execution, under a predictable name built from the submission time, the field name and the client-supplied file name. Contact Form 7 renames files with extensions such as .php or .phtml, but other types such as .phar, .html or .svg are stored as uploaded. This makes it possible for unauthenticated attackers to upload files that may make remote code execution possible on servers configured to execute .phar files, or that lead to stored cross-site scripting through HTML or SVG content. Exploitation requires a form that contains the plugin's Signature field and a submission whose notification email is sent successfully.

## References

- https://wpsec.com/vuln/WPSEC-2026-0469/
- https://plugins.svn.wordpress.org/extensions-for-cf7/tags/3.4.6/
- https://wordpress.org/plugins/extensions-for-cf7/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0469/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
