Junglewise Threat Intelligence

CVE-2026-90984: Generate PDF using Contact Form 7 Server-Side Request Forgery

CVE-2026-90984 · Severity: medium · CVSS 5.8 · Published 2026-09-18

Executive brief

Generate PDF using Contact Form 7 is a WordPress plugin that allows website owners to create PDF documents from contact form submissions. The plugin contains a vulnerability that allows attackers to make the server fetch arbitrary internal resources and expose their contents through generated PDFs, potentially exposing sensitive configuration files, credentials, or other protected data without requiring authentication.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability in the PDF renderer component. The plugin fails to validate or restrict the destination URLs when fetching images during PDF generation, allowing an unauthenticated attacker to inject malicious form fields that trigger requests to internal resources. An attacker can submit a form with an array-valued field containing an internal resource URL (e.g., file:// or local IP paths), and the server's response is reflected back in the generated PDF. No authentication is required; the attack surface is any publicly accessible form using this plugin. The vulnerability was patched in version 4.2.2.

Affected products

  • Artus Generate PDF using Contact Form 7 before 4.2.2

Timeline

  • 2026-09-16: disclosed
  • 2026-09-18: advisory
  • 2026-09-18: patched: Fixed in version 4.2.2

References