Conversation
supportHola, Me acaba de saltar este aviso de seguridad para las versiones <=5.0.5: https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Gracias! The page I need help with: [ log in to see the link]
Gracias, pero esto ya se ha solucionado. Patchstack tarda en verificar: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/
Hi there, Jumping on this as I’ve a client with this plugin and recording security bugs. I’d suggest that the issue is potentially still there. Patchstack tends to (from my experience) verifies the plugin when you upload a new version to the repository. The fact that 5.0.5 is reporting the issue is still unfixed (and the latest version is being the source of the vulnerability) means it’s probably checked. Patchstack I tend to find are pretty helpful if you’re having issues in patching it.
Hola! Sí, como dice el compañero, la versión que todavía parece que tiene el bug es la última versión: 5.0.5 Esperamos a que lo soluciones. Gracias!
Tengo el mismo problema aquí: https://hcda-akademie.de Patchstack habla de la versión <= 5.0.5. Por lo tanto, parece que afecta a la versión actual. Gracias!
This thread does NOT seem to be resolved at all 🙁
I don’t know what else to say. I did what I needed to do: patch the code and publish it in WordPress, notify Patchstack of the patch. The patch has been pending on my end for over a month; I can’t make them review it faster, especially one they have deemed as a low priority. I don’t know what their usual turnaround time is for triage and verification. Sorry. Read this: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/
¿Alguna novedad para corregir la vulnerabilidad de la versión 5.0.5? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability
On Patchstack, the bug is now listed as “no official patch available” instead of “pending.” Version 5.0.5 has also already been released. Did the fix not work? Does it need to be corrected again? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Thank you very much En Patchstack, el estado del error ahora es «no hay parches oficiales disponibles» y ya no «pendiente». Además, la versión 5.0.5 ya se ha lanzado. ¿No ha funcionado la corrección del error? ¿Hay que volver a corregirlo? Muchas gracias
Subscribing for follow-up
Gracias, pero esto ya se ha solucionado. Patchstack tarda en verificar: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/
Hi there, Jumping on this as I’ve a client with this plugin and recording security bugs. I’d suggest that the issue is potentially still there. Patchstack tends to (from my experience) verifies the plugin when you upload a new version to the repository. The fact that 5.0.5 is reporting the issue is still unfixed (and the latest version is being the source of the vulnerability) means it’s probably checked. Patchstack I tend to find are pretty helpful if you’re having issues in patching it.
Hola! Sí, como dice el compañero, la versión que todavía parece que tiene el bug es la última versión: 5.0.5 Esperamos a que lo soluciones. Gracias!
Tengo el mismo problema aquí: https://hcda-akademie.de Patchstack habla de la versión <= 5.0.5. Por lo tanto, parece que afecta a la versión actual. Gracias!
This thread does NOT seem to be resolved at all 🙁
I don’t know what else to say. I did what I needed to do: patch the code and publish it in WordPress, notify Patchstack of the patch. The patch has been pending on my end for over a month; I can’t make them review it faster, especially one they have deemed as a low priority. I don’t know what their usual turnaround time is for triage and verification. Sorry. Read this: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/
¿Alguna novedad para corregir la vulnerabilidad de la versión 5.0.5? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability
On Patchstack, the bug is now listed as “no official patch available” instead of “pending.” Version 5.0.5 has also already been released. Did the fix not work? Does it need to be corrected again? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Thank you very much En Patchstack, el estado del error ahora es «no hay parches oficiales disponibles» y ya no «pendiente». Además, la versión 5.0.5 ya se ha lanzado. ¿No ha funcionado la corrección del error? ¿Hay que volver a corregirlo? Muchas gracias
Subscribing for follow-up