---
id: CVE-2026-90984
title: >-
  The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not
  restrict the destination of the image fetch its PDF renderer performs on
  submitted form content, allowing unauthenticated users to make the server
  request inter…
summary: >-
  The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not
  restrict the destination of the image fetch its PDF renderer performs on
  submitted form content, allowing unauthenticated users to make the server
  request inter…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
product: Generate PDF using Contact Form 7
affected:
  - generate_pdf_using_contact_form_7 < 4.2.2
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90984'
references:
  - url: 'https://wpscan.com/vulnerability/1aa459e4-bd75-49a5-a6de-812375d441e6/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00323
epssPercentile: 0.2268
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T10:59:58.273568Z'
ingestedAt: '2026-09-18T06:36:37.988Z'
---

## Overview

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
