Summary
What it is: An Arbitrary File Upload vulnerability, CVE-2026-84750.
Who it affects: The Ultra Addons for Contact Form 7 plugin for WordPress.
Is it patched: Yes, a patch is available in version 3.5.51.
Is it being exploited: No active exploitation has been observed.
Affected and patched versions
Status | Version Range |
|---|---|
Affected | 3.2.4 to 3.5.50 |
Patched | 3.5.51 and later |
Is my site vulnerable?
To determine if your WordPress site uses a vulnerable version of the Ultra Addons for Contact Form 7 plugin, you can check the installed plugin version through your WordPress administration dashboard.
Log in to your WordPress admin area.
Navigate to the "Plugins" section in the left-hand menu.
Locate "Ultra Addons for Contact Form 7" in the list of installed plugins.
The version number is displayed next to the plugin name.
If the displayed version is between 3.2.4 and 3.5.50, your site is running a vulnerable version of the plugin. If the version is 3.5.51 or higher, your site is running the patched version. This check provides a direct way to verify your plugin status.
What an attacker actually does
The vulnerability, identified as CVE-2026-84750, exists within the Ultra Addons for Contact Form 7 plugin for WordPress. This issue stems from the plugin's failure to properly validate the type or extension of files uploaded through one of its form fields. This missing file type validation creates an opportunity for unauthenticated attackers to upload arbitrary files to the affected site's server. The uploaded files are then stored at a predictable public path, retaining the attacker-chosen extension.
An attacker can exploit this by submitting a file through a form field provided by the Ultra Addons for Contact Form 7 plugin. Since the plugin does not adequately check the file type, the attacker can specify a dangerous file extension. For example, they might choose a .phar extension. If the web server is configured to execute .phar files as PHP scripts, which is a common configuration on some Debian and Ubuntu Apache setups, the attacker can then access this uploaded .phar file directly. This action causes the server to execute malicious code embedded within the file, potentially leading to Remote Code Execution (RCE) and a full site takeover.
Alternatively, an attacker might upload a file with a .php extension. If the server is configured to handle .php files, the file is served with its script intact. This can result in Stored Cross-Site Scripting (XSS). In an XSS scenario, when a legitimate user accesses a page that loads the malicious script, their browser executes the attacker's code. This could lead to actions such as stealing user session cookies, defacing the website, or redirecting users to malicious sites. The critical aspect of this vulnerability is that no special user account or prior authentication is needed for an attacker to carry out these actions.
How to detect a compromise
Detecting a compromise related to CVE-2026-84750 involves looking for unusual or unauthorized files on your server, particularly in directories where user uploads are typically stored. The vulnerability allows attackers to upload arbitrary files to a predictable public path.
Key indicators of compromise include:
Unexpected Files in Upload Directories: Look for files with suspicious names or extensions in your WordPress upload directories, commonly
wp-content/uploads/. Attackers might upload files with executable extensions such as.phpor.phar.Files with Unusual Content: Even if a file has a seemingly innocuous extension, its content might reveal malicious intent. Look for PHP code in files that should not contain it, or files that appear to be web shells or backdoors.
Server Logs: Review your web server access logs (e.g., Apache
access.log, Nginxaccess.log) for requests to unusual files or paths, especially those within upload directories that do not correspond to legitimate media uploads. Look for direct access attempts to.phpor.pharfiles inwp-content/uploads/or other public directories.New or Modified User Accounts: A successful Remote Code Execution could allow an attacker to create new administrator accounts or modify existing ones. Check your WordPress user list for any unauthorized additions or changes.
Website Defacement or Malicious Redirects: Visible changes to your website's content or unexpected redirects to other sites can indicate a compromise. This might be a direct result of an uploaded malicious script.
To search for potentially malicious files, you can use command-line tools on your server. For example, to find .php or .phar files in your wp-content/uploads directory, you can use the find command:
find /path/to/your/wordpress/wp-content/uploads -type f \( -name "*.php" -o -name "*.phar" \)Replace /path/to/your/wordpress with the actual path to your WordPress installation. This command will list all files ending with .php or .phar within the specified directory and its subdirectories. Review any files found carefully to determine if they are legitimate.
How to fix
Addressing CVE-2026-84750 requires immediate action to secure your WordPress site. Follow these steps to mitigate the vulnerability:
Update the plugin: The primary remediation is to update the Ultra Addons for Contact Form 7 plugin to version 3.5.51 or later. This version contains the necessary patch to address the arbitrary file upload vulnerability. Ensure you back up your site before performing any updates.
Implement server-side controls: Configure your web server to restrict executable file uploads in directories designated for user-generated content. This can involve using web server rules (e.g.,
.htaccessfor Apache, Nginx configuration) to prevent script execution in specific folders, such aswp-content/uploads/.Validate file types strictly: Beyond the plugin's internal validation, consider implementing additional server-side checks to strictly validate file types based on their content (MIME type) rather than just their extension. This provides a deeper layer of security against misidentified or maliciously renamed files.
Store uploads outside the web root: If feasible, configure your WordPress installation to store user uploads in a directory located outside the publicly accessible web root. This prevents direct web access to uploaded files, even if they contain malicious scripts.
Configure the web server to not execute scripts from upload directories: Explicitly instruct your web server not to execute scripts (like PHP or PHAR files) from your upload directories. For Apache, this might involve using
php_flag engine offorRemoveHandler .php .phtml .php3 .php4 .php5 .php6 .phardirectives in an.htaccessfile within the upload directory. For Nginx, similar directives can be added to the server block configuration.
Timeline
Date | Event |
|---|---|
2026-09-19 | Vulnerability Published |
2026-09-19 | Vulnerability Modified |
2026-09-19 | Vulnerability Published |
2026-09-19 | Vulnerability Updated |
Sources
https://nvd.nist.gov/vuln/detail/CVE-2026-84750
https://www.wordfence.com/threat-intel/vulnerabilities/id/77b19085-4a7f-4554-bbad-46aa9ab10fc5
https://wordpress.org/plugins/ultimate-addons-for-contact-form-7/
https://nvd.nist.gov/vuln/detail/cve-2026-84750
https://www.tenable.com/cve/CVE-2026-84750