Arbitrary Shortcode Execution Vulnerability in Contact Form 7 – Dynamic Text Extension Plugin for WordPress
CVE-2025-13146
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2025-13146?
The Contact Form 7 – Dynamic Text Extension plugin for WordPress exhibits a vulnerability that permits arbitrary shortcode execution in all versions up to and including 5.0.6. This flaw arises from the plugin's inadequate validation of input values before executing the do_shortcode function, potentially allowing unauthenticated attackers to execute arbitrary shortcodes on affected sites. Although a partial patch was introduced in version 5.0.4, the vulnerability remains present in earlier versions, posing a threat to up-to-date security measures.
Affected Version(s)
Contact Form 7 – Dynamic Text Extension 0 <= 5.0.3