Critical severity9.8NVD Advisory· Published Oct 10, 2026
CVE-2026-94589
CVE-2026-94589
Description
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.4.5
Patches
Vulnerability mechanics
References
7- plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/admin/include/class.cf7-signature.phpnvd
- plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/admin/include/class.cf7-signature.phpnvd
- plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/includes/class.cf7-extensions.phpnvd
- plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/includes/class.form-data-store.phpnvd
- plugins.trac.wordpress.org/changeset/3727009/extensions-for-cf7/trunk/admin/include/class.cf7-signature.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/fa3193c4-dd3e-4d9e-be42-769c7358beaenvd
News mentions
0No linked articles in our index yet.