Impact
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to and including 5.0.7. The flaw occurs because the plugin does not properly validate a value before running do_shortcode, allowing unauthenticated attackers to inject and execute arbitrary shortcodes. The impact is the ability for unauthorized users to run shortcodes within the plugin, potentially leading to further malicious actions. The vulnerability was partially patched in version 5.0.4 but remains in 5.0.7.
Affected Systems
All WordPress sites that include the sevenspark Contact Form 7 – Dynamic Text Extension plugin with a version number of 5.0.7 or earlier are affected. No other products are listed.
Risk and Exploitability
The CVSS flaw in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. It is not listed in CISA’s KEV catalog. Attackers can trigger this flaw by sending unauthenticated HTTP requests that cause the likely attack vector is network‑ web. All versions up to and including 5.0.7 are affected.
OpenCVE Enrichment