What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: from n/a through <= 4.1.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Generate PDF using Contact Form 7 plugin for WordPress allows authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that may be executed on the server, potentially compromising the entire site. The vulnerability affects all versions up to 4.1.2.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files on the server with admin-level access.
Potential impact on your site
04Site Impact
A compromised admin account can lead to full site takeover, data theft, or malware installation.
Conditions required to exploit
05Prerequisites
Attacker must have WordPress administrator privileges; no user interaction required.
Key dates
06Disclosure timeline
July 9, 2024
CVE published
April 28, 2026
Record updated