plugin

Contact Form 7 Vulnerabilities

28 known security issues reported for the Contact Form 7 WordPress plugin. Most recent disclosed Apr 15, 2025.

3 critical 2 high 9 medium

Running Contact Form 7 on your site? Check whether your installed version is affected.

Scan your site free

Contact Form 7 <= 6.0.5 - Order Replay Vulnerability

medium

The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multi...

CVSS:
5.3
Affected:
up to 6.0.5
Fixed in:
6.0.6
Disclosed:
Apr 15, 2025

CVE-2025-3247 on NVD →

Contact Form 7 < 6.0.6 - Order Replay Vulnerability

unknown
Affected:
up to 6.0.6
Fixed in:
6.0.6
Disclosed:
Apr 15, 2025

CVE-2025-3247 on NVD →

Contact Form 7 [contact-form-7] < 5.9.5

unknown

[en] The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

Affected:
up to 5.9.5
Fixed in:
5.9.5
Disclosed:
Jun 27, 2024

CVE-2024-4704 on NVD →

Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect

medium
Affected:
up to 5.9.5
Fixed in:
5.9.5
Disclosed:
Jun 5, 2024

CVE-2024-4704 on NVD →

Contact Form 7 <= 5.9.4 - Unauthenticated Open Redirect

medium

The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 5.9.4. This is due to insufficient validation on the redirect url supplied via accessing the contact form with a spoofed page. This makes it possible for unauthenticated attackers to redirect site users to poten...

CVSS:
6.1
Affected:
up to 5.9.4
Fixed in:
5.9.5
Disclosed:
Jun 5, 2024

CVE-2024-4704 on NVD →

Contact Form 7 <= 5.9 - Reflected Cross-Site Scripting

medium

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 5.9
Fixed in:
5.9.2
Disclosed:
Mar 13, 2024

CVE-2024-2242 on NVD →

Contact Form 7 [contact-form-7] < 5.9.2

unknown

[en] The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 5.9.2
Fixed in:
5.9.2
Disclosed:
Mar 13, 2024

CVE-2024-2242 on NVD →

Contact Form 7 < 5.9.2 - Reflected Cross-Site Scripting

medium
Affected:
up to 5.9.2
Fixed in:
5.9.2
Disclosed:
Mar 13, 2024

CVE-2024-2242 on NVD →

Contact Form 7 [contact-form-7] < 5.8.4

unknown

[en] The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers...

Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
Dec 1, 2023

CVE-2023-6449 on NVD →

Contact Form 7 <= 5.8.3 - Authenticated (Editor+) Arbitrary File Upload

medium

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with...

CVSS:
6.6
Affected:
up to 5.8.3
Fixed in:
5.8.4
Disclosed:
Nov 30, 2023

CVE-2023-6449 on NVD →

Contact Form 7 < 5.8.4 - Authenticated (Editor+) Arbitrary File Upload

high
Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
Nov 30, 2023

CVE-2023-6449 on NVD →

Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass

high

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads in versions up to 5.3.2. This is due to the fact that the plugin allows filenames to contain special characters which may make extension filter evasion possible on certain configurations. Our team was not able to reproduce this issue which...

CVSS:
8.1
Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Dec 17, 2020

CVE-2020-35489 on NVD →

Contact Form 7 [contact-form-7] < 5.3.2

unknown

[en] The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Dec 17, 2020

CVE-2020-35489 on NVD →

Contact Form 7 [contact-form-7] < 5.3.2

unknown

Unrestricted File Upload vulnerability found by Jinson Varghese Behanan in WordPress Contact Form 7 plugin (versions <= 5.3.1).

Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Dec 17, 2020

Contact Form 7 < 5.3.2 - Unrestricted File Upload

medium
Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Dec 17, 2020

CVE-2020-35489 on NVD →

Contact Form 7 [contact-form-7] < 5.0.4

unknown

[en] The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Aug 22, 2019

CVE-2018-20979 on NVD →

Contact Form 7 [contact-form-7] < 5.0.4

unknown

Privilege Escalation vulnerability found by Simon Scannell in WordPress Contact Form 7 plugin (versions <= 5.0.3).

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Sep 13, 2018

Contact Form 7 <= 5.0.3 - Authorization Bypass

medium

The Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to capability_type mishandling in register_post_type in versions up to, and including, 5.0.3. This makes it possible for authenticated attackers with contributor level privileges and above to modify contact forms and potential supply path...

CVSS:
6.3
Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Sep 4, 2018

CVE-2018-20979 on NVD →

Contact Form 7 <= 5.0.3 - register_post_type() Privilege Escalation

critical
Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Sep 4, 2018

CVE-2018-20979 on NVD →

Contact Form 7 <= 3.5.2 - File Upload Remote Code Execution

critical
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Aug 1, 2014

Contact Form 7 <= 3.7.1 - CAPTCHA Bypass

unknown
Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Aug 1, 2014

CVE-2014-2265 on NVD →

Contact Form 7 <= 3.5.2 - Arbitrary File Upload

critical

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on contact form uploads in versions up to, and including, 3.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...

CVSS:
9.8
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Aug 1, 2014

Contact Form 7 [contact-form-7] < 3.5.3

unknown

Because of this vulnerability, attackers with admin access add uploader tag into contact form at the site and use it for CE via AFU attack. Update the plugin.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Aug 1, 2014

Contact Form 7 [contact-form-7] < 3.5.3

unknown

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on contact form uploads in versions up to, and including, 3.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Aug 1, 2014

Contact Form 7 [contact-form-7] < 3.7.2

unknown

[en] Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Mar 14, 2014

CVE-2014-2265 on NVD →

Contact Form 7 < 3.7.2 - CAPTCHA Bypass

medium

Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.

CVSS:
5.3
Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Feb 26, 2014

CVE-2014-2265 on NVD →

Contact Form 7 [contact-form-7] < 3.5.3

unknown

The Contact Form 7 WordPress plugin was affected by a File Upload Remote Code Execution security vulnerability.

Affected:
up to 3.5.3
Fixed in:
3.5.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database