Input validation vulnerability in Contact Form 7 – Dynamic Text Extension 2.0.3

. The Contact Form 7 Dynamic Text Extension plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This security issue affects versions up to, and including, 2.0.3 of the plugin. If the vulnerability is present, it means that someone with contributor level permissions or higher can inject malicious web scripts into a page. When a user visits the affected page, the malicious script will be executed.

Detected in:

Contact Form 7 – Dynamic Text Extension fixed vulnerable versions: >= * <= 2.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.