Contact Form 7

Contact Form 7 is a WordPress plugin that allows users to manage multiple contact forms and customize them with simple markup. The plugin supports Ajax-powered submitting, CAPTCHA, and Akismet spam filtering. Users can find documentation, FAQs, and support on the Contact Form 7 website and WordPress.org. The plugin does not track users, write personal data to the database, send data to external servers, or use cookies by default. However, activating certain features may send personal data to service providers, so users should confirm their privacy policies. The plugin relies on user donations to continue development and support.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Contact Form 7 6.0.5

    Fixed

    The Contact Form 7 plugin for WordPress has a security issue that allows unauthorized users to make multiple transactions using the same payment information. This happens because the plugin does not ...

    Read More
  • Input validation vulnerability in Contact Form 7 5.9.4

    Fixed

    The Contact Form 7 plugin for WordPress has a security issue where it can be manipulated to redirect users to harmful websites. This can happen when someone sends a fake webpage link through the cont...

    Read More
  • Input validation vulnerability in Contact Form 7 5.9

    Fixed

    The Contact Form 7 plugin for WordPress has a security vulnerability that allows attackers to inject harmful code into web pages. This can happen if they can trick a user into clicking on a link. The...

    Read More
  • Input validation vulnerability in Contact Form 7 5.8.3

    Fixed

    The Contact Form 7 plugin for WordPress, which is used to create contact forms for websites, has a security issue in versions up to 5.8.3. This vulnerability allows attackers who have editor-level ac...

    Read More
  • Weak configuration vulnerability in Contact Form 7 3.7.2

    Fixed

    A security vulnerability has been discovered in the Rock Lobster Contact Form 7 plugin

    Read More
  • Input validation vulnerability in Contact Form 7 3.5.2

    Fixed

    The Contact Form 7 plugin for WordPress, which is up to version 3.5.2, has a vulnerability that allows unauthenticated attackers to upload any type of file to the server. This could allow them to exe...

    Read More
  • Input validation vulnerability in Contact Form 7 5.3.2

    Fixed

    The Contact Form 7 plugin for WordPress used to be vulnerable to something called ""arbitrary file uploads"" if you used version 5.3.2 or earlier. This is because it allowed filenames that had special...

    Read More
  • Access violation vulnerability in Contact Form 7 5.0.4

    Fixed

    The Contact Form 7 plugin for WordPress is not secure enough in versions up to 5.0.3. This means that people with certain levels of access can change contact forms and access sensitive files that coul...

    Read More