Impact
The Contact Form 7 – Dynamic Text Extension plugin allows stored cross‑site scripting when an authenticated user with Editor or higher privileges edits form shortcode keys. The plugin fails to escape output of these keys on the admin “Scan Forms for Post Meta and User Data Keys” page. An attacker can inject JavaScript that will run in the context of an Administrator who later activates the scan, enabling script execution and potential defacement or credential theft.
Affected Systems
All WordPress installations that use the Contact Form 7 – Dynamic Text Extension plugin up to and including version 5.0.5 are affected. No specific operating system or server configuration limits the vulnerability; the issue resides entirely in the plugin code.
Risk and Exploitability
The CVSS v3.1 score is 4.4, indicating a moderate severity. The EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated and hold at least Editor rights; the attack vector is local with privileged access. Once the script is injected, any Administrator who runs the scan routine will have it executed, enabling a range of XSS‑based attacks such as cookie theft, session hijacking, or site defacement.
OpenCVE Enrichment