CVE-2026-82901

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-26); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-26: 3Mentions · 2026-09-27: 109-2609-27
Referenced assets3 URLs
Full discourse4 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 WordPress Ultra Addons for Contact Form 7 eklentisinde, 3.5.50 ve önceki sürümleri etkileyen kritik bir dosya yükleme açığı (CVE-2026-82901) bulundu. CVSS 9.8 Critical. Kimlik doğrulaması gerektirmeyen saldırganlar, PDF Generator modülü etkinse arbitrary file upload gerçekleştirebiliyor; uygun sunucu yapılandırmalarında bu durum RCE'ye yol açabiliyor. ⚠️ Eklentiyi 3.5.51 veya daha yeni sürüme güncellemelisiniz.

    00030215
    2.4K followersView on X
  • mürrez@murrezsec

    New vulnerability analysis & PoC live! 🔍 Deep dive into CVE-2026-82901 mechanics, details, and mitigation: 💻 https://pocbit.org/pocs/cve-2026-82901 Feedback and reviews are always welcome. #VulnerabilityResearch #CyberSecurity #RedTeam #Exploit #CVE

    1002095
    607 followersView on X
  • CVE@CVEnew

    CVE-2026-82901 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_comp… https://www.cve.org/CVERecord?id=CVE-2026-82901

    00000713
    58.1K followersView on X
  • PJ@Npj8448

    🚨 ShinyHunters is bypassing WAFs to exploit Oracle PeopleSoft servers using URL-encoding tricks. Meanwhile, critical CVE-2026-82901 hits WordPress Ultra Addons with CVSS 9.8 file uploads. Check your web logs and patch now. #ThreatIntel #CyberSecurity #CVE https://pranithjain.qzz.io/threatintel/telegram?tab=firehose

    0000052
    77 followersView on X

Explore more