Web Application Vulnerability in Contact Form 7 Dynamic Text Extension by SevenSpark
CVE-2025-63068

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-63068?

The Contact Form 7 Dynamic Text Extension plugin for WordPress is susceptible to a vulnerability that allows for improper neutralization of script-related HTML tags. This flaw enables attackers to inject malicious code into web pages via crafted input. As a result, this could lead to unauthorized actions or data exposure, compromising the security of websites using affected versions up to 5.0.3. Website administrators should promptly assess and implement security measures to mitigate this threat.

Affected Version(s)

Contact Form 7 Dynamic Text Extension <= n/a

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Najib Sinjari | Patchstack Bug Bounty Program
.