Unrated severityNVD Advisory· Published Sep 18, 2026
CVE-2026-90984
CVE-2026-90984
Description
The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.2.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.