Ultra Addons for Contact Form 7 <= 3.5.54 - Unauthenticated HTML Injection to Server-Side Request Forgery via PDF Generator Form Field Values
- ID
- WPSEC-2026-0776
- Plugin
- Ultra Addons for Contact Form 7 (ultimate-addons-for-contact-form-7)
- Affected
- all versions before 3.5.55
- Remediation
- Update to 3.5.55 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-918
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-11
- Attack surface
- Ultra Addons for Contact Form 7 on WPSec AttackSurface
- Fix released
- Published
Description
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Server-Side Request Forgery via the PDF Generator addon in all versions up to, and including, 3.5.54. This is due to submitted form field values, including repeater values, being placed unescaped into the HTML template that mPDF renders. This makes it possible for unauthenticated attackers to inject HTML markup, such as image tags pointing to internal or arbitrary URLs. The server then makes requests to those URLs when it builds the PDF, and the attacker can also add arbitrary content to the generated PDF. Exploitation requires the PDF Generator addon to be enabled for a form whose PDF template includes the affected field.
References
- https://wpsec.com/vuln/WPSEC-2026-0776/
- https://plugins.svn.wordpress.org/ultimate-addons-for-contact-form-7/tags/3.5.55/
- https://wordpress.org/plugins/ultimate-addons-for-contact-form-7/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS