Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Contact Form 7 - Security Vulnerability (CVE-2026-73386)
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7
CVE-2026-73386
Contact Form 7 - Broken Access Control (CVE-2026-66660)
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-66660
Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-5116)
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.
CVE-2026-5116
Contact Form 7 - Improper Input Validation (CVE-2026-14236)
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
CVE-2026-14236
The Contact Form 7 - Security Vulnerability (CVE-2025-13146)
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.
CVE-2025-13146
Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-57423)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through
CVE-2026-57423
Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-57411)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through
CVE-2026-57411
Contact Form 7 - PHP Object Injection (CVE-2026-9691)
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
CVE-2026-9691
Contact Form 7 - PHP Object Injection (CVE-2026-49765)
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
CVE-2026-49765
Contact Form 7 - PHP Object Injection (CVE-2026-49109)
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
CVE-2026-49109
Contact Form 7 - PHP Object Injection (CVE-2026-49106)
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact
CVE-2026-49106
Contact Form 7 - PHP Object Injection (CVE-2026-49105)
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49105
Contact Form 7 - PHP Object Injection (CVE-2026-49104)
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
CVE-2026-49104
Contact Form 7 - PHP Object Injection (CVE-2026-49085)
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49085
Contact Form 7 - Security Vulnerability (CVE-2026-9189)
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with `cmd=_notify-validate`, it fails to compare the IPN payload's `mc_gross` (payment amount), `mc_currency`, or `receiver_email` fields against the corresponding stored order values before passing the attacker-controlled `invoice` field directly to `cf7pp_complete_payment()`, which marks the order completed after only an integer cast with no amount verification. This makes it…
CVE-2026-9189
Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-42728)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through
CVE-2026-42728
Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2022-50960)
WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.
CVE-2022-50960
Contact Form 7 - Arbitrary File Upload (CVE-2026-5710)
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is directly appended to the plugin's upload URL without sanitization. In dnd_cf7_mail_components(), the URL is converted back to a filesystem…
CVE-2026-5710
Contact Form 7 - Broken Access Control (CVE-2026-39707)
Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through
CVE-2026-39707
Contact Form 7 - Broken Access Control (CVE-2026-32527)
Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through
CVE-2026-32527