WPIntell

Source evidence

Content Injection Vulnerability

Contact Form 7 – Dynamic Text Extension · support · 2025-12-09T16:36:00+00:00

questionsentiment
highseverity
0.95relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 18 rows with source links

38.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

11 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
kkow resolved
Hi, Is this being worked on? When will a fix be available? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Hi @kkow , this is something I am aware of. It’ is currently low on my list of priorities because the “bug” that is reported is one of the primary “features” which is the ability to code your own shortcodes and run them through CF7, and the vulnerability is that I am not validating or verifying any of your custom shortcodes. While we have permissions in place for using allowlists in our built-in shortcodes , I think we will have to do the same with custom shortcodes, as in, make an allowlist of shortcodes and their attributes and permissions. I have to put more thought into it. It will definitely inhibit a lot of users and break a lot of sites if implemented poorly. I’m open to suggestions if you have any 🙂 Hey fam, I’ll be working on this today. Stay tuned! Just posting an update to say I am still focusing on this, this week. I’m still coding the update; the next version from me will be version 6.0.0 because I’m overhauling a lot of the under-the-hood code to use namespaces and classes and to keep plugin itself as light as possible (I hate unnecessary bloat). The settings page is also getting updated to handle the needed allow lists. Once I move into the testing phase, I’ll also be writing documentation alongside it, so you’ll likely see that on my website before it’s released. For those of you who want to keep getting these updates, click the “subscribe” button on the sidebar of this thread. Thanks! I just released version 5.0.4 to patch the vulnerability. If the plugin is set to update automatically on your site(s), then there’s nothing else you need to do. I shelved the updates for version 6 so I could publish this patch today. Thank you for your patience!

Comments

4 shown
Tessa (they/them), AuRise Creative 2025-12-09T18:50:00+00:00

Hi @kkow , this is something I am aware of. It’ is currently low on my list of priorities because the “bug” that is reported is one of the primary “features” which is the ability to code your own shortcodes and run them through CF7, and the vulnerability is that I am not validating or verifying any of your custom shortcodes. While we have permissions in place for using allowlists in our built-in shortcodes , I think we will have to do the same with custom shortcodes, as in, make an allowlist of shortcodes and their attributes and permissions. I have to put more thought into it. It will definitely inhibit a lot of users and break a lot of sites if implemented poorly. I’m open to suggestions if you have any 🙂

Tessa (they/them), AuRise Creative 2025-12-10T16:31:00+00:00

Hey fam, I’ll be working on this today. Stay tuned!

Tessa (they/them), AuRise Creative 2025-12-15T14:59:00+00:00

Just posting an update to say I am still focusing on this, this week. I’m still coding the update; the next version from me will be version 6.0.0 because I’m overhauling a lot of the under-the-hood code to use namespaces and classes and to keep plugin itself as light as possible (I hate unnecessary bloat). The settings page is also getting updated to handle the needed allow lists. Once I move into the testing phase, I’ll also be writing documentation alongside it, so you’ll likely see that on my website before it’s released. For those of you who want to keep getting these updates, click the “subscribe” button on the sidebar of this thread. Thanks!

Tessa (they/them), AuRise Creative 2026-01-01T23:59:00+00:00

I just released version 5.0.4 to patch the vulnerability. If the plugin is set to update automatically on your site(s), then there’s nothing else you need to do. I shelved the updates for version 6 so I could publish this patch today. Thank you for your patience!