CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host
highThe CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_trigger. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and mo...
- CVSS:
- 7.2
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.1
- Disclosed:
- Jun 17, 2026