WPHizmet

Eklenti güvenlik geçmişi

Ultra Addons for Contact Form 7 güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Ultra Addons for Contact Form 7 eklentisi için 7 açık kaydı bulunuyor; en yenisi 26 Eylül 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 3 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.5.54.

Toplam kayıt
7
Kritik veya yüksek
2
Oturumsuz istismar
3
Son kayıt
26 Eylül 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-82901Kritik · 9,826 Eylül 2026

    kısıtlamasız dosya yükleme

    Etkilenen sürümler: 3.5.50 ve öncesi · Oturum açmadan istismar edilebilir

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-84750Orta · 6,519 Eylül 2026

    uzaktan kod çalıştırma

    Etkilenen sürümler: 3.5.51 öncesi · Oturum açmadan istismar edilebilir

    The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP alongside .php and .phtml, so on that stack the uploaded file is executed and the issue leads to Remote Code Execution and full site takeover. Where the host routes only .php to the PHP handler, the same file is instead served from the site's own origin with its script intact, leading to Stored Cross-Site Scripting.

  • CVE-2026-12801Orta · 6,47 Ağustos 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.5.43 ve öncesi

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2025-14356Orta · 4,312 Aralık 2025

    yetkisiz nesne erişimi (IDOR)

    Etkilenen sürümler: 3.5.33 ve öncesi

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

  • CVE-2025-6756Orta · 5,41 Temmuz 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.5.21 ve öncesi

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and including, 3.5.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2025-6212Orta · 6,126 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The unfiltered field names are stored alongside the sanitized values. Later, the admin-side AJAX endpoint ajax_get_table_data() returns those raw names as JSON column headers, and the client-side DataTables renderer injects them directly into the DOM without any HTML encoding. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2025-6220Yüksek · 7,218 Haziran 2025

    kısıtlamasız dosya yükleme

    Etkilenen sürümler: 3.5.12 ve öncesi

    The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.