Ultra Addons for Contact Form 7 <= 3.5.54 - Unauthenticated Stored Cross-Site Scripting via Form File Uploads

High 7.2 CWE-79Fixed in 3.5.55
ID
WPSEC-2026-0775
Plugin
Ultra Addons for Contact Form 7 (ultimate-addons-for-contact-form-7)
Affected
all versions before 3.5.55
Remediation
Update to 3.5.55 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-11
Attack surface
Ultra Addons for Contact Form 7 on WPSec AttackSurface
Fix released
Published

Description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form file uploads in all versions up to, and including, 3.5.54. This is due to insufficient content validation of text-type uploads and the database addon copying uploaded files into the publicly accessible uacf7-uploads directory without a file extension and without any protection against MIME sniffing. This makes it possible for unauthenticated attackers to upload files containing HTML or script that execute in the browser of a user who accesses the stored file, such as an administrator reviewing submissions.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0