• PoC PUBLIC

CVE-2026-82901: pre-auth arbitrary file upload in themefic Ultra Addons for Contact Form 7

Unauthenticated attackers can upload files to sites running the Ultra Addons for Contact Form 7 WordPress plugin, potentially leading to remote code execution; tracked as CVE-2026-82901. The flaw affects 3.x branch releases 3.5.50 and earlier. Exploitation requires the plugin's PDF Generator module to be enabled on the target site (that module is off by default), and network access to the vulnerable WordPress instance is sufficient.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01109
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available for an unauthenticated file-upload flaw that can enable remote code execution if the PDF Generator module is enabled, so treat internet-facing sites with this plugin as high priority to mitigate.

What is CVE-2026-82901?

Unauthenticated attackers can upload files to sites running the Ultra Addons for Contact Form 7 WordPress plugin, potentially leading to remote code execution; tracked as CVE-2026-82901. The flaw affects 3.x branch releases 3.5.50 and earlier. Exploitation requires the plugin's PDF Generator module to be enabled on the target site (that module is off by default), and network access to the vulnerable WordPress instance is sufficient. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of themefic Ultra Addons for Contact Form 7 are affected?

BRANCHAFFECTEDFIXED
3.x3.5.50 and earlier

Is CVE-2026-82901 being exploited?

Public exploit code is available.

How to fix CVE-2026-82901

  1. Disable the plugin's PDF Generator module immediately if it is enabled.
  2. Restrict access to WordPress admin and upload endpoints from untrusted networks and block unauthenticated access where possible.
  3. Monitor webserver and upload directories for unexpected files and review logs for suspicious POST requests to the plugin endpoints.
  4. Follow the vendor's guidance and install a vendor-supplied update once a fixed release is published.

Frequently asked questions

Is CVE-2026-82901 being actively exploited?

Public exploit code is available for CVE-2026-82901.

Which Ultra Addons for Contact Form 7 versions are affected by CVE-2026-82901?

The vulnerability affects the 3.x branch, specifically versions 3.5.50 and earlier.

Is there a patch for CVE-2026-82901?

No fixed release is listed for Ultra Addons for Contact Form 7 as of the provided information; monitor the vendor for an official update.

Does CVE-2026-82901 require authentication?

No. The issue can be exploited without authentication when the plugin's PDF Generator module is enabled.

References