WPIntell

Source evidence

Parche seguridad <=5.0.5

Contact Form 7 – Dynamic Text Extension · support · 2026-02-23T19:19:00+00:00

mixedsentiment
highseverity
0.94relevance
9replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 18 rows with source links

38.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

11 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
joaquinpalazon resolved
Hola, Me acaba de saltar este aviso de seguridad para las versiones <=5.0.5: https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Gracias! The page I need help with: [ log in to see the link] Gracias, pero esto ya se ha solucionado. Patchstack tarda en verificar: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/ Hi there, Jumping on this as I’ve a client with this plugin and recording security bugs. I’d suggest that the issue is potentially still there. Patchstack tends to (from my experience) verifies the plugin when you upload a new version to the repository. The fact that 5.0.5 is reporting the issue is still unfixed (and the latest version is being the source of the vulnerability) means it’s probably checked. Patchstack I tend to find are pretty helpful if you’re having issues in patching it. Hola! Sí, como dice el compañero, la versión que todavía parece que tiene el bug es la última versión: 5.0.5 Esperamos a que lo soluciones. Gracias! Tengo el mismo problema aquí: https://hcda-akademie.de Patchstack habla de la versión <= 5.0.5. Por lo tanto, parece que afecta a la versión actual. Gracias! This thread does NOT seem to be resolved at all 🙁 I don’t know what else to say. I did what I needed to do: patch the code and publish it in WordPress, notify Patchstack of the patch. The patch has been pending on my end for over a month; I can’t make them review it faster, especially one they have deemed as a low priority. I don’t know what their usual turnaround time is for triage and verification. Sorry. Read this: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/ ¿Alguna novedad para corregir la vulnerabilidad de la versión 5.0.5? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability On Patchstack, the bug is now listed as “no official patch available” instead of “pending.” Version 5.0.5 has also already been released. Did the fix not work? Does it need to be corrected again? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Thank you very much En Patchstack, el estado del error ahora es «no hay parches oficiales disponibles» y ya no «pendiente». Además, la versión 5.0.5 ya se ha lanzado. ¿No ha funcionado la corrección del error? ¿Hay que volver a corregirlo? Muchas gracias Subscribing for follow-up

Comments

9 shown
Tessa (they/them), AuRise Creative 2026-02-23T19:41:00+00:00

Gracias, pero esto ya se ha solucionado. Patchstack tarda en verificar: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/

Rhys Wynne 2026-02-24T11:55:00+00:00

Hi there, Jumping on this as I’ve a client with this plugin and recording security bugs. I’d suggest that the issue is potentially still there. Patchstack tends to (from my experience) verifies the plugin when you upload a new version to the repository. The fact that 5.0.5 is reporting the issue is still unfixed (and the latest version is being the source of the vulnerability) means it’s probably checked. Patchstack I tend to find are pretty helpful if you’re having issues in patching it.

joaquinpalazon 2026-02-24T14:42:00+00:00

Hola! Sí, como dice el compañero, la versión que todavía parece que tiene el bug es la última versión: 5.0.5 Esperamos a que lo soluciones. Gracias!

collaborato 2026-02-25T08:16:00+00:00

Tengo el mismo problema aquí: https://hcda-akademie.de Patchstack habla de la versión <= 5.0.5. Por lo tanto, parece que afecta a la versión actual. Gracias!

Gal Baras 2026-02-28T22:58:00+00:00

This thread does NOT seem to be resolved at all 🙁

Tessa (they/them), AuRise Creative 2026-03-01T00:33:00+00:00

I don’t know what else to say. I did what I needed to do: patch the code and publish it in WordPress, notify Patchstack of the patch. The patch has been pending on my end for over a month; I can’t make them review it faster, especially one they have deemed as a low priority. I don’t know what their usual turnaround time is for triage and verification. Sorry. Read this: https://aurisecreative.com/blog/2026/01/wpcf7dtx-security-vulnerability-cve-2025-13146/

joaquinpalazon 2026-03-04T17:51:00+00:00

¿Alguna novedad para corregir la vulnerabilidad de la versión 5.0.5? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability

collaborato 2026-03-18T09:25:00+00:00

On Patchstack, the bug is now listed as “no official patch available” instead of “pending.” Version 5.0.5 has also already been released. Did the fix not work? Does it need to be corrected again? https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Thank you very much En Patchstack, el estado del error ahora es «no hay parches oficiales disponibles» y ya no «pendiente». Además, la versión 5.0.5 ya se ha lanzado. ¿No ha funcionado la corrección del error? ¿Hay que volver a corregirlo? Muchas gracias

TRILOS new media 2026-03-31T11:26:00+00:00

Subscribing for follow-up