Medium 6.5
2026-03-14< 3.5.37
Ultra Addons for Contact Form 7 <= 3.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
3.5.37
Update to 3.5.37 or later to address 14 fixable vulnerabilities
Ultra Addons for Contact Form 7 <= 3.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2026-24945
CVE-2025-14356
Ultra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode
Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database module
WordPress Ultimate Addons for Contact Form 7 Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload
CVE-2023-49766
CVE-2023-47693
CVE-2023-30493
CVE-2023-2803
CVE-2023-2802
CVE-2023-1615
CVE-2022-47586
CVE-2023-30495