CVE-2026-90984

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.

  • Published Sep 18, 2026
  • CVSS 5.8 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-90984 at the National Vulnerability Database