WPIntell

Source evidence

Vulnerability Wordfence

Contact Form 7 – Dynamic Text Extension · support · 2026-03-09T09:58:00+00:00

mixedsentiment
highseverity
0.94relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 18 rows with source links

38.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

11 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
roccsont resolved
Hi, I would like to ask, if this vulnerability is known and if a solutions is beeing worked out? Thank you! https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-7-dynamic-text-extension/contact-form-7-dynamic-text-extension-503-unauthenticated-arbitrary-shortcode-execution Subscribing for follow-up Yes to both questions. When a security vulnerability is reported on either the Wordfence Intelligence Vulnerability Submission Form or the Patchstack Vulnerability Disclosure Program , I am now automatically notified. More often than not, the report remains private until it is patched to avoid adding additional risks to sites by disclosing details. For updates on this particular report, please see this article here on my website or send me an email. It is for that same reason that I do not disclose vulnerability report details publicly. Patchstack reviewed the patch submitted in version 5.0.5 on March 24, 2026, and marked it as incomplete , meaning the immediate vulnerability has been patched but the security around it could be hardened even more. These additional security features will be added in the upcoming version 6 of Contact Form 7 – Dynamic Text Extension . I do not yet have a timeline for its release. —April 8, 2026 For the security of all users, please do not report security bugs or vulnerabilities in these support forums . Thank you!

Comments

2 shown
TRILOS new media 2026-03-31T11:18:00+00:00

Subscribing for follow-up

Tessa (they/them), AuRise Creative 2026-04-08T13:40:00+00:00

Yes to both questions. When a security vulnerability is reported on either the Wordfence Intelligence Vulnerability Submission Form or the Patchstack Vulnerability Disclosure Program , I am now automatically notified. More often than not, the report remains private until it is patched to avoid adding additional risks to sites by disclosing details. For updates on this particular report, please see this article here on my website or send me an email. It is for that same reason that I do not disclose vulnerability report details publicly. Patchstack reviewed the patch submitted in version 5.0.5 on March 24, 2026, and marked it as incomplete , meaning the immediate vulnerability has been patched but the security around it could be hardened even more. These additional security features will be added in the upcoming version 6 of Contact Form 7 – Dynamic Text Extension . I do not yet have a timeline for its release. —April 8, 2026 For the security of all users, please do not report security bugs or vulnerabilities in these support forums . Thank you!