CVE-2026-82901
Ultra Addons for Contact Form 7 (WordPress) unauthenticated arbitrary file upload in uacf7_wpcf7_mail_components -> possible RCE
- Severity
- critical
- Affected product
- ultimate-addons-for-contact-form-7
- Affected versions
- ultimate-addons-for-contact-form-7 ≤ 3.5.50
- Fixed in
- ultimate-addons-for-contact-form-7 3.5.51
- Added to NewScan
- 2026-09-27
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints ultimate-addons-for-contact-form-7 from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-27 (/daily-cve). CVSS 9.8. The 'uacf7_wpcf7_mail_components' function validates file type insufficiently, so unauthenticated attackers can upload arbitrary files to the webroot, which may make remote code execution possible. Version source: scan_wordpress mines every referenced plugin slug from asset `?ver=` and refines it against /wp-content/plugins/<slug>/readme.txt `Stable tag:` - the same generic per-slug join the other WordPress rows in this pack use, no new code. THE SLUG IS VERIFIED, NOT INFERRED: the CVE title says 'Ultra Addons' but the directory is `ultimate-addons-for-contact-form-7` - api.wordpress.org/plugins/info/1.0/ultimate-addons-for-contact-form-7.json answers with the display name 'Ultra Addons for Contact Form 7' at version 3.5.52, confirming the directory name the readme join needs and that a fix above 3.5.50 shipped. Keyed on the slug and not the display name, because the readme join only ever sees the directory. Version-match only, and the row is deliberately wider than the exploit: it fires on a vulnerable version, while exploitation additionally requires the PDF Generator module to be enabled (disabled by default) - a module state nothing anonymous reveals. No in-band probe: proving the upload means writing a file to a stranger's server.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →