cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-form-7-dynamic-text-extension contact-form-7-dynamic-text-extension

Direction: ascending
Jun 07, 2024

Contact Form 7 – Dynamic Text Extension # a96df0f01268aec2ea27d8015425dd3a2aec921e

Date
Jul 26, 2019
Research Description
Contact Form 7 &#8211; Dynamic Text Extension [contact-form-7-dynamic-text-extension] < 3.0.0 (closed) WordPress Contact Form 7 Dynamic Text Extension plugin <= 2.0.2.1 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Contact Form 7 Dynamic Text Extension plugin (versions <= 2.0.2.1).
Affected versions
Min -, max -.
Status
vulnerable

Contact Form 7 &#8211; Dynamic Text Extension # CVE-2023-6630

CVE, Research URL

CVE-2023-6630

Date
Jan 11, 2024
Research Description
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missing validation on a user controlled key. This makes it possible for authenticated attackers with contributor access or higher to access arbitrary metadata of any post type, referencing the post by id and the meta by key.
Affected versions
Min -, max -.
Status
vulnerable
Nov 07, 2024

Contact Form 7 &#8211; Dynamic Text Extension # CVE-2024-10084

CVE, Research URL

CVE-2024-10084

Date
Nov 06, 2024
Research Description
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.
Affected versions
Min -, max -.
Status
vulnerable
Dec 23, 2024

Contact Form 7 &#8211; Dynamic Text Extension # CVE-2024-56218

CVE, Research URL

CVE-2024-56218

Date
Dec 31, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in AuRise Creative, SevenSpark Contact Form 7 Dynamic Text Extension allows Cross Site Request Forgery.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through 5.0.1.
Affected versions
Min -, max -.
Status
vulnerable