Description
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.
Published: 2026-08-05
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Contact Form 7 – Dynamic Text Extension plugin allows stored cross‑site scripting when an authenticated user with Editor or higher privileges edits form shortcode keys. The plugin fails to escape output of these keys on the admin “Scan Forms for Post Meta and User Data Keys” page. An attacker can inject JavaScript that will run in the context of an Administrator who later activates the scan, enabling script execution and potential defacement or credential theft.

Affected Systems

All WordPress installations that use the Contact Form 7 – Dynamic Text Extension plugin up to and including version 5.0.5 are affected. No specific operating system or server configuration limits the vulnerability; the issue resides entirely in the plugin code.

Risk and Exploitability

The CVSS v3.1 score is 4.4, indicating a moderate severity. The EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated and hold at least Editor rights; the attack vector is local with privileged access. Once the script is injected, any Administrator who runs the scan routine will have it executed, enabling a range of XSS‑based attacks such as cookie theft, session hijacking, or site defacement.

Generated by OpenCVE AI on August 5, 2026 at 08:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Dynamic Text Extension plugin to version 5.0.6 or later.
  • Restrict usage of the “Scan Forms” feature to administrators or remove the feature for users with only Editor privileges.
  • Monitor administrator activity logs for unexpected JavaScript execution or unauthorized changes to form settings.

Generated by OpenCVE AI on August 5, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sevenspark
Sevenspark dtx – Dynamic Text Extension For Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Sevenspark
Sevenspark dtx – Dynamic Text Extension For Contact Form 7
Wordpress
Wordpress wordpress

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.
Title Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Sevenspark Dtx – Dynamic Text Extension For Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-05T13:51:18.761Z

Reserved: 2026-03-29T23:06:36.721Z

Link: CVE-2026-5116

cve-icon Vulnrichment

Updated: 2026-08-05T13:51:14.518Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:18:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')