cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcf7-conditional-fields cf7-conditional-fields

Direction: ascending
Jun 07, 2024

Conditional Fields for Contact Form 7 # 0bb038577e135241efdec5ee2901e7ead90280e7

Date
Nov 14, 2023
Research Description
Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.4.1 (closed) Conditional Fields for Contact Form 7 <= 2.4.0 - Missing Authorization The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when showing admin notices in all versions up to 2.4.0 (inclusive). This makes it possible for attackers to read admin notices.
Affected versions
max 2.4.1.
Status
vulnerable
Jun 10, 2024

Conditional Fields for Contact Form 7 # CVE-2023-47838

CVE, Research URL

CVE-2023-47838

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.1.
Affected versions
max 2.4.2.
Status
vulnerable
Jul 20, 2024

Conditional Fields for Contact Form 7 # CVE-2024-5804

CVE, Research URL

CVE-2024-5804

Date
Jul 20, 2024
Research Description
The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.4.14.
Status
vulnerable
Oct 27, 2024

Conditional Fields for Contact Form 7 # CVE-2024-50412

CVE, Research URL

CVE-2024-50412

Date
Oct 29, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Stored XSS.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.15.
Affected versions
max 2.5.
Status
vulnerable
May 06, 2026

Conditional Fields for Contact Form 7 # CVE-2026-25863

CVE, Research URL

CVE-2026-25863

Date
May 05, 2026
Research Description
Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or upper bound enforcement. Unauthenticated attackers can supply an arbitrarily large integer value through the REST API endpoint to cause unbounded loop execution with multiple preg_replace() operations, exhausting server memory and crashing the PHP process.
Affected versions
max 2.6.7.
Status
vulnerable