# Ultra Addons for Contact Form 7 <= 3.5.54 - Unauthenticated HTML Injection to Server-Side Request Forgery via PDF Generator Form Field Values

- **ID:** WPSEC-2026-0776
- **Plugin:** Ultra Addons for Contact Form 7 (`ultimate-addons-for-contact-form-7`), https://wordpress.org/plugins/ultimate-addons-for-contact-form-7/
- **Affected versions:** all versions before 3.5.55
- **Fixed in:** 3.5.55 (Update to 3.5.55 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-918
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/ultimate-addons-for-contact-form-7
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0776/

## Description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Server-Side Request Forgery via the PDF Generator addon in all versions up to, and including, 3.5.54. This is due to submitted form field values, including repeater values, being placed unescaped into the HTML template that mPDF renders. This makes it possible for unauthenticated attackers to inject HTML markup, such as image tags pointing to internal or arbitrary URLs. The server then makes requests to those URLs when it builds the PDF, and the attacker can also add arbitrary content to the generated PDF. Exploitation requires the PDF Generator addon to be enabled for a form whose PDF template includes the affected field.

## References

- https://wpsec.com/vuln/WPSEC-2026-0776/
- https://plugins.svn.wordpress.org/ultimate-addons-for-contact-form-7/tags/3.5.55/
- https://wordpress.org/plugins/ultimate-addons-for-contact-form-7/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0776/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
