CVE-2026-94664: WordPress PDF for Contact Form 7 plugin <= 7.1.0 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Path Traversal.This issue affects PDF for Contact Form 7: from n/a through 7.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PDF for Contact Form 7to a version that resolves this vulnerability.Fixed in 7.2.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it is remotely exploitable over the network with low attack complexity, requires no privileges, and requires no user interaction.
What is the likely impact if exploitation succeeds?
The issue is identified as an arbitrary file download and path traversal vulnerability. Its CVSS vector indicates high confidentiality impact, with no integrity or availability impact specified.
Which plugin versions are affected?
PDF for Contact Form 7 is affected through version 7.1.0. The provided data does not identify a fixed version.