CVE-2026-84750: Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Field

Published Sep 19, 2026
·
Updated

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP alongside .php and .phtml, so on that stack the uploaded file is executed and the issue leads to Remote Code Execution and full site takeover. Where the host routes only .php to the PHP handler, the same file is instead served from the site's own origin with its script intact, leading to Stored Cross-Site Scripting.

Affected Software

3 affected components
WordPress plugin Ultra Addons for Contact Form 7<3.5.51
WordPress plugin Ultimate Addons for Contact Form 7>=3.2.4<=3.5.50
Apache Apache HTTP Server

Event History

Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments face remote code execution rather than only stored cross-site scripting?

Deployments using the plugin with the default PHP handler configuration shipped by Debian and Ubuntu Apache packages are exposed to remote code execution, because those handlers map .phar files to PHP. On hosts that route only .php to PHP, uploaded content is served from the site origin and results in stored cross-site scripting instead.

2

Does an attacker need an account or other authentication to exploit this?

No. The vulnerable signature-field upload path can be used by unauthenticated users.

3

What version resolves the issue?

Upgrade the plugin to version 3.5.51 or later. Versions before 3.5.51 are affected.

4

How can I determine whether uploaded files could be executed as PHP?

Check the Apache/PHP handler mapping for the affected host. If .phar is mapped to the PHP handler, as in the default Debian and Ubuntu Apache package configuration described, an attacker-uploaded .phar file can be executed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203