Sceawere

Vulnerability Detail

CVE-2026-94666UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Path Traversal in Generate PDF

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
ZealousWeb
Product
Generate PDF using Contact Form 7
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-09T10:16:41.690Z",
  "pubdate": "2026-10-09T10:16:41.690Z",
  "executiveSummary": "The Generate PDF using Contact Form 7 plugin, version 4.2.1 and earlier, is susceptible to a Path Traversal vulnerability (CWE-22).\nThis vulnerability arises from the improper sanitization of user-supplied input paths, which allows an attacker to break out of the intended directory structure.\nBy manipulating file path parameters, a remote, unauthenticated attacker can access, read, or potentially manipulate sensitive files located outside the plugin's designated web root directory.\nThis poses a critical risk to the confidentiality and integrity of the underlying WordPress environment, potentially leading to the disclosure of configuration files, database credentials, or sensitive system data.\nThe exploit requires no specific authentication, making it a high-priority security concern for site administrators using the affected software.",
  "technicalDetails": "The vulnerability is identified as a classic Path Traversal (CWE-22) issue within the Generate PDF using Contact Form 7 plugin, impacting versions up to and including 4.2.1.\nThe root cause of this flaw is the insufficient validation and sanitization of input arguments that are subsequently passed to file system APIs. When the application processes requests involving PDF generation or file handling, it fails to verify that the target file path remains confined within the expected directory.\nAn attacker can exploit this by injecting directory traversal sequences—most commonly the dot-dot-slash ('../') sequence—into the vulnerable parameter. By iteratively applying these sequences, the attacker can navigate upward through the file system hierarchy, escaping the sandbox intended for the plugin's operation.\nThe attack flow typically follows these steps: 1) Identification of the vulnerable input parameter responsible for file path construction; 2) Crafting of a malicious payload containing relative path segments; 3) Submission of the payload via a crafted HTTP request (typically GET or POST); 4) The application's server-side logic resolves the manipulated path, effectively pointing to unauthorized files; 5) The server processes the request and returns the contents of the target file to the attacker or performs operations on the targeted system file.\nSince the plugin operates within the WordPress environment, successful exploitation allows the attacker to reach files beyond the web-accessible directory. This may include sensitive files such as wp-config.php, which contains critical database credentials, secret keys, and other server-side configuration data.\nThe impact is significant because the vulnerability does not require authentication, allowing any remote visitor to traverse the file system. The post-exploitation impact includes the full compromise of sensitive data, potential configuration modification, and a significant reduction in the overall security posture of the host server."
}
CVE-2026-94666: Path Traversal in Generate PDF (HIGH Severity, CVSS: 7.5) | Sceawere