Sceawere

Vulnerability Detail

CVE-2026-94664UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Path Traversal in PDF for Contact Form 7

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
add-ons.org
Product
PDF for Contact Form 7
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Path Traversal.This issue affects PDF for Contact Form 7: from n/a through 7.1.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-09T10:16:41.420Z",
  "pubdate": "2026-10-09T10:16:41.420Z",
  "executiveSummary": "This vulnerability is identified as an Improper Limitation of a Pathname to a Restricted Directory, commonly referred to as Path Traversal, impacting the 'PDF for Contact Form 7' plugin for WordPress.\nThe flaw exists in versions from n/a through 7.1.0 and allows an unauthenticated or authenticated attacker to bypass intended file system restrictions.\nBy manipulating input parameters that influence file paths, an attacker can traverse the directory structure to access sensitive files located outside the plugin's designated directory.\nThe risk implication is significant, as successful exploitation may result in the unauthorized disclosure of configuration files, credentials, or other sensitive system data residing on the server.\nThe vulnerability arises from insufficient validation and sanitization of user-supplied input used in file system operations. Attackers require no specialized privileges to potentially trigger this behavior, depending on the specific implementation, and the attack is executed via standard HTTP requests targeting the vulnerable plugin functionality.",
  "technicalDetails": "The vulnerability stems from the application's failure to properly sanitize or validate user-controlled input before utilizing it in file path construction for read or inclusion operations.\nSpecifically, the 'PDF for Contact Form 7' plugin fails to implement robust input filtering to prevent the injection of path traversal sequences, such as '../', into parameters processed by its file-handling mechanisms.\nIn a typical attack flow, an adversary identifies an input parameter responsible for file retrieval, such as those used for generating or downloading PDF files. The attacker then replaces the expected filename or path with a sequence of dot-dot-slash ('../') characters followed by the target file path (e.g., /etc/passwd or wp-config.php).\nBecause the application does not properly normalize the path or verify that the requested file resides within the permitted directory context, the underlying operating system or file API resolves the malicious path to the unintended target location.\nIf the application logic then proceeds to read the contents of the resolved path and returns them to the user, the attacker gains unauthorized read access to system files.\nThe vulnerability is present in versions 7.1.0 and earlier. The scope of the impact is determined by the permissions of the web server process (e.g., www-data), which dictates the files the attacker can successfully access.\nThis flaw is categorized under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The absence of secure input handling mechanisms like basename validation, path canonicalization, or the use of allow-lists for file access enables this traversal. There is no indication that authentication is required to interact with the vulnerable file-handling routine, potentially exposing the server to remote attackers via the web interface."
}
CVE-2026-94664: Path Traversal in PDF for Contact Form 7 (HIGH Severity, CVSS: 7.5) | Sceawere