Arbitrary Shortcode Execution Vulnerability in Contact Form 7 – Dynamic Text Extension Plugin for WordPress
CVE-2025-13146

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 July 2026

What is CVE-2025-13146?

The Contact Form 7 – Dynamic Text Extension plugin for WordPress exhibits a vulnerability that permits arbitrary shortcode execution in all versions up to and including 5.0.6. This flaw arises from the plugin's inadequate validation of input values before executing the do_shortcode function, potentially allowing unauthenticated attackers to execute arbitrary shortcodes on affected sites. Although a partial patch was introduced in version 5.0.4, the vulnerability remains present in earlier versions, posing a threat to up-to-date security measures.

Affected Version(s)

Contact Form 7 – Dynamic Text Extension 0 <= 5.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NosleeP++
.