← All CVEs NewScan detects
critical

CVE-2026-82901

Ultra Addons for Contact Form 7 (WordPress) unauthenticated arbitrary file upload in uacf7_wpcf7_mail_components -> possible RCE

Severity
critical
Affected product
ultimate-addons-for-contact-form-7
Affected versions
ultimate-addons-for-contact-form-7 ≤ 3.5.50
Fixed in
ultimate-addons-for-contact-form-7 3.5.51
Added to NewScan
2026-09-27
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints ultimate-addons-for-contact-form-7 from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-27 (/daily-cve). CVSS 9.8. The 'uacf7_wpcf7_mail_components' function validates file type insufficiently, so unauthenticated attackers can upload arbitrary files to the webroot, which may make remote code execution possible. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - the same generic per-slug join the other WordPress rows in this pack use, no new code. THE SLUG IS VERIFIED, NOT INFERRED: the CVE title says 'Ultra Addons' but the directory is `ultimate-addons-for-contact-form-7` - api.wordpress.org/plugins/info/1.0/ultimate-addons-for-contact-form-7.json answers with the display name 'Ultra Addons for Contact Form 7' at version 3.5.52, confirming the directory name the readme join needs and that a fix above 3.5.50 shipped. Keyed on the slug and not the display name, because the readme join only ever sees the directory. Version-match only, and the row is deliberately wider than the exploit: it fires on a vulnerable version, while exploitation additionally requires the PDF Generator module to be enabled (disabled by default) - a module state nothing anonymous reveals. No in-band probe: proving the upload means writing a file to a stranger's server.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →