Answer in brief
CVE-2026-94589 records a Critical severity (CVSS 9.8) vulnerability in Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload. The current sources do not mark it as known exploited. The current feed maps htplugins/Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps htplugins/Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| htplugins/Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)generic | >=0 <=3.4.5 | Not reported |
Published upstream
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 10, 2026
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Quoted source text, attributed separately from HOL analysis.