VYPR

Ultra Addons for Contact Form 7

by WordPress

CVEs (7)

  • CVE-2026-82901CriSep 26, 2026
    risk 0.57cvss 9.8epss 0.01

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated…

  • CVE-2026-84750MedSep 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to…

  • CVE-2025-6212HigJun 26, 2025
    risk 0.40cvss 7.2epss 0.00

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The unfiltered field names are stored alongside the sanitized…

  • CVE-2025-6220HigJun 18, 2025
    risk 0.40cvss 7.2epss 0.01

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with…

  • CVE-2026-12801MedAug 7, 2026
    risk 0.35cvss 6.4epss 0.00

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This…

  • CVE-2025-6756MedJul 1, 2025
    risk 0.35cvss 6.4epss 0.00

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and including, 3.5.21 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2025-14356MedDec 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers,…