CVE-2026-94666: WordPress Generate PDF using Contact Form 7 plugin <= 4.2.1 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/generate-pdf-using-contact-form-7to a version that resolves this vulnerability.Fixed in 4.2.2
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The supplied CVSS vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction required. This means an unauthenticated remote attacker may be able to target an affected site.
What is the potential impact?
The issue is described as path traversal leading to arbitrary file download. The CVSS vector indicates high confidentiality impact, with no stated integrity or availability impact.
Which versions are affected?
Generate PDF using Contact Form 7 versions through 4.2.1 are affected. The lower bound is listed as n/a, so the provided data does not identify an unaffected earlier version or a fixed version.