sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total104
Critical17
High29
Medium57
Reset
Showing 1-20 of 104 records
Threat Entry Updated 2026-08-12

Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-5116)

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.

PLUGIN Contact Form 7

CVE-2026-5116

MEDIUM CVSS 4.4 2026-08-05
Threat Entry Updated 2026-07-27

Contact Form 7 - Improper Input Validation (CVE-2026-14236)

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.

PLUGIN Contact Form 7

CVE-2026-14236

MEDIUM CVSS 4.7 2026-07-27
Threat Entry Updated 2026-07-22

The Contact Form 7 - Security Vulnerability (CVE-2025-13146)

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.

PLUGIN The Contact Form 7

CVE-2025-13146

MEDIUM CVSS 6.5 2026-07-22
Threat Entry Updated 2026-07-13

Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-57423)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-57423

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2026-57411)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-57411

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-21

Contact Form 7 - Security Vulnerability (CVE-2026-9189)

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with `cmd=_notify-validate`, it fails to compare the IPN payload's `mc_gross` (payment amount), `mc_currency`, or `receiver_email` fields against the corresponding stored order values before passing the attacker-controlled `invoice` field directly to `cf7pp_complete_payment()`, which marks the order completed after only an integer cast with no amount verification. This makes it…

PLUGIN Contact Form 7

CVE-2026-9189

MEDIUM CVSS 5.3 2026-05-29
Threat Entry Updated 2026-07-24

Contact Form 7 - Cross-Site Scripting (XSS) (CVE-2022-50960)

WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.

PLUGIN Contact Form 7

CVE-2022-50960

MEDIUM CVSS 5.1 2026-05-10
Threat Entry Updated 2026-06-17

Contact Form 7 - Arbitrary File Upload (CVE-2026-5710)

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is directly appended to the plugin's upload URL without sanitization. In dnd_cf7_mail_components(), the URL is converted back to a filesystem…

PLUGIN Contact Form 7

CVE-2026-5710

HIGH CVSS 7.5 2026-04-17
Threat Entry Updated 2026-07-24

Contact Form 7 - Broken Access Control (CVE-2026-39707)

Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-39707

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-06-17

Contact Form 7 - Broken Access Control (CVE-2026-32527)

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through

PLUGIN Contact Form 7

CVE-2026-32527

MEDIUM CVSS 6.5 2026-03-25