Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
medium
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multi...
- CVSS:
- 5.3
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.6
- Disclosed:
- Apr 15, 2025
CVE-2025-3247 on NVD →
Contact Form 7 < 6.0.6 - Order Replay Vulnerability
unknown
- Affected:
- up to 6.0.6
- Fixed in:
- 6.0.6
- Disclosed:
- Apr 15, 2025
CVE-2025-3247 on NVD →
Contact Form 7 [contact-form-7] < 5.9.5
unknown
[en] The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Jun 27, 2024
CVE-2024-4704 on NVD →
Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect
medium
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Jun 5, 2024
CVE-2024-4704 on NVD →
Contact Form 7 <= 5.9.4 - Unauthenticated Open Redirect
medium
The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 5.9.4. This is due to insufficient validation on the redirect url supplied via accessing the contact form with a spoofed page. This makes it possible for unauthenticated attackers to redirect site users to poten...
- CVSS:
- 6.1
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.5
- Disclosed:
- Jun 5, 2024
CVE-2024-4704 on NVD →
Contact Form 7 <= 5.9 - Reflected Cross-Site Scripting
medium
The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 5.9
- Fixed in:
- 5.9.2
- Disclosed:
- Mar 13, 2024
CVE-2024-2242 on NVD →
Contact Form 7 [contact-form-7] < 5.9.2
unknown
[en] The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 5.9.2
- Fixed in:
- 5.9.2
- Disclosed:
- Mar 13, 2024
CVE-2024-2242 on NVD →
Contact Form 7 < 5.9.2 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 5.9.2
- Fixed in:
- 5.9.2
- Disclosed:
- Mar 13, 2024
CVE-2024-2242 on NVD →
Contact Form 7 [contact-form-7] < 5.8.4
unknown
[en] The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers...
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.4
- Disclosed:
- Dec 1, 2023
CVE-2023-6449 on NVD →
Contact Form 7 <= 5.8.3 - Authenticated (Editor+) Arbitrary File Upload
medium
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with...
- CVSS:
- 6.6
- Affected:
- up to 5.8.3
- Fixed in:
- 5.8.4
- Disclosed:
- Nov 30, 2023
CVE-2023-6449 on NVD →
Contact Form 7 < 5.8.4 - Authenticated (Editor+) Arbitrary File Upload
high
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.4
- Disclosed:
- Nov 30, 2023
CVE-2023-6449 on NVD →
Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass
high
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads in versions up to 5.3.2. This is due to the fact that the plugin allows filenames to contain special characters which may make extension filter evasion possible on certain configurations. Our team was not able to reproduce this issue which...
- CVSS:
- 8.1
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Dec 17, 2020
CVE-2020-35489 on NVD →
Contact Form 7 [contact-form-7] < 5.3.2
unknown
[en] The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Dec 17, 2020
CVE-2020-35489 on NVD →
Contact Form 7 [contact-form-7] < 5.3.2
unknown
Unrestricted File Upload vulnerability found by Jinson Varghese Behanan in WordPress Contact Form 7 plugin (versions <= 5.3.1).
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Dec 17, 2020
Contact Form 7 < 5.3.2 - Unrestricted File Upload
medium
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Dec 17, 2020
CVE-2020-35489 on NVD →
Contact Form 7 [contact-form-7] < 5.0.4
unknown
[en] The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Aug 22, 2019
CVE-2018-20979 on NVD →
Contact Form 7 [contact-form-7] < 5.0.4
unknown
Privilege Escalation vulnerability found by Simon Scannell in WordPress Contact Form 7 plugin (versions <= 5.0.3).
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Sep 13, 2018
Contact Form 7 <= 5.0.3 - Authorization Bypass
medium
The Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to capability_type mishandling in register_post_type in versions up to, and including, 5.0.3. This makes it possible for authenticated attackers with contributor level privileges and above to modify contact forms and potential supply path...
- CVSS:
- 6.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Sep 4, 2018
CVE-2018-20979 on NVD →
Contact Form 7 <= 5.0.3 - register_post_type() Privilege Escalation
critical
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Sep 4, 2018
CVE-2018-20979 on NVD →
Contact Form 7 <= 3.5.2 - File Upload Remote Code Execution
critical
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Aug 1, 2014
Contact Form 7 <= 3.7.1 - CAPTCHA Bypass
unknown
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Aug 1, 2014
CVE-2014-2265 on NVD →
Contact Form 7 <= 3.5.2 - Arbitrary File Upload
critical
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on contact form uploads in versions up to, and including, 3.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...
- CVSS:
- 9.8
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Aug 1, 2014
Contact Form 7 [contact-form-7] < 3.5.3
unknown
Because of this vulnerability, attackers with admin access add uploader tag into contact form at the site
and use it for CE via AFU attack.
Update the plugin.
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Aug 1, 2014
Contact Form 7 [contact-form-7] < 3.5.3
unknown
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on contact form uploads in versions up to, and including, 3.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Aug 1, 2014
Contact Form 7 [contact-form-7] < 3.7.2
unknown
[en] Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Mar 14, 2014
CVE-2014-2265 on NVD →
Contact Form 7 < 3.7.2 - CAPTCHA Bypass
medium
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
- CVSS:
- 5.3
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Feb 26, 2014
CVE-2014-2265 on NVD →
Contact Form 7 [contact-form-7] < 3.5.3
unknown
The Contact Form 7 WordPress plugin was affected by a File Upload Remote Code Execution security vulnerability.
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
Contact Form 7 [contact-form-7] < 6.0.6
unknown
- Affected:
- up to 6.0.6
- Fixed in:
- 6.0.6
CVE-2025-3247 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database