Ultra Addons for Contact Form 7 <= 3.5.54 - Unauthenticated HTML Injection to Server-Side Request Forgery via PDF Generator Form Field Values

Medium 5.4 CWE-918Fixed in 3.5.55
ID
WPSEC-2026-0776
Plugin
Ultra Addons for Contact Form 7 (ultimate-addons-for-contact-form-7)
Affected
all versions before 3.5.55
Remediation
Update to 3.5.55 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-918
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-11
Attack surface
Ultra Addons for Contact Form 7 on WPSec AttackSurface
Fix released
Published

Description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Server-Side Request Forgery via the PDF Generator addon in all versions up to, and including, 3.5.54. This is due to submitted form field values, including repeater values, being placed unescaped into the HTML template that mPDF renders. This makes it possible for unauthenticated attackers to inject HTML markup, such as image tags pointing to internal or arbitrary URLs. The server then makes requests to those URLs when it builds the PDF, and the attacker can also add arbitrary content to the generated PDF. Exploitation requires the PDF Generator addon to be enabled for a form whose PDF template includes the affected field.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0