sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-12

Dynamic Text Extension - Cross-Site Scripting (XSS) (CVE-2026-5116)

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.

PLUGIN Dynamic Text Extension

CVE-2026-5116

MEDIUM CVSS 4.4 2026-08-05
Threat Entry Updated 2025-07-11

Dynamic Text Extension - Information Disclosure (CVE-2024-10084)

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.

PLUGIN Dynamic Text Extension

CVE-2024-10084

MEDIUM CVSS 4.3 2024-11-05
Threat Entry Updated 2024-11-21

Dynamic Text Extension - Security Vulnerability (CVE-2023-6630)

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missing validation on a user controlled key. This makes it possible for authenticated attackers with contributor access or higher to access arbitrary metadata of any post type, referencing the post by id and the meta by key.

PLUGIN Dynamic Text Extension

CVE-2023-6630

MEDIUM CVSS 4.3 2024-01-11