A Contact Form 7 plugin bug lets anyone upload files to your server
Ultra Addons for Contact Form 7 has a critical unauthenticated file upload flaw when its PDF Generator module is switched on. Version 3.5.51 fixes it.
A critical vulnerability in Ultra Addons for Contact Form 7, tracked as CVE-2026-82901, was disclosed on 26 September with a CVSS score of 9.8. It affects every version up to and including 3.5.50 of the plugin, built by themefic.
The flaw sits in the uacf7_wpcf7_mail_components function, which fails to validate file type or extension when a form’s signature field is submitted. An unauthenticated attacker can upload a file with any extension straight to a predictable path, wp-content/uploads/uacf7-uploads/, and on stacks that will execute PHP from the uploads directory that means remote code execution. It only triggers when the plugin’s PDF Generator module is enabled, which is off by default. Version 3.5.51 adds the missing type checking.
Why it matters: if you’ve turned on PDF Generator for e-signature forms, this is a patch-now situation, not a wait-and-see one — unauthenticated file upload with a working path to RCE is exactly the kind of bug that gets automated scanners pointed at it within days of disclosure.
The caveat: exposure is limited to sites that switched PDF Generator on. If you’ve never touched that setting, you’re not affected, but it’s worth checking rather than assuming.