WPIntell

Source evidence

Warning : Content Injection vulnerability

Contact Form 7 – Dynamic Text Extension · support · 2026-03-19T10:49:00+00:00

mixedsentiment
highseverity
0.95relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 18 rows with source links

38.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

11 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
tabasko resolved
Hi dear support team, Are you aware about this vulnerability ? any fix ? Thanks to keep us informed please https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-3-content-injection-vulnerability Subscribing for follow-up Any update after 2 weeks ? Please let us know. If the security bug or vulnerability is already on those platforms, then I already know about it. They notify me now and provide me with additional report details and technical support as the developer responsible for patching it. To stay updated on this particular report, please see this article here on my website or send me an email. I do not disclose vulnerability report details publicly for security purposes so if that is what you’re looking for, an email is best. Patchstack reviewed the patch submitted in version 5.0.5 on March 24, 2026, and marked it as incomplete , meaning the immediate vulnerability has been patched but the security around it could be hardened even more. These additional security features will be added in the upcoming version 6 of Contact Form 7 – Dynamic Text Extension . I do not yet have a timeline for its release. —April 8, 2026 For the security of all users, please do not report security bugs or vulnerabilities in these support forums . Instead, use either the Wordfence Intelligence Vulnerability Submission Form or the Patchstack Vulnerability Disclosure Program . Both platforms will assist you with verification, CVE assignment, and notify me.

Comments

3 shown
TRILOS new media 2026-03-31T11:18:00+00:00

Subscribing for follow-up

tabasko 2026-04-07T19:04:00+00:00

Any update after 2 weeks ? Please let us know.

Tessa (they/them), AuRise Creative 2026-04-08T13:33:00+00:00

If the security bug or vulnerability is already on those platforms, then I already know about it. They notify me now and provide me with additional report details and technical support as the developer responsible for patching it. To stay updated on this particular report, please see this article here on my website or send me an email. I do not disclose vulnerability report details publicly for security purposes so if that is what you’re looking for, an email is best. Patchstack reviewed the patch submitted in version 5.0.5 on March 24, 2026, and marked it as incomplete , meaning the immediate vulnerability has been patched but the security around it could be hardened even more. These additional security features will be added in the upcoming version 6 of Contact Form 7 – Dynamic Text Extension . I do not yet have a timeline for its release. —April 8, 2026 For the security of all users, please do not report security bugs or vulnerabilities in these support forums . Instead, use either the Wordfence Intelligence Vulnerability Submission Form or the Patchstack Vulnerability Disclosure Program . Both platforms will assist you with verification, CVE assignment, and notify me.