Web Application Vulnerability in Contact Form 7 Dynamic Text Extension by SevenSpark
CVE-2025-63068
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63068?
The Contact Form 7 Dynamic Text Extension plugin for WordPress is susceptible to a vulnerability that allows for improper neutralization of script-related HTML tags. This flaw enables attackers to inject malicious code into web pages via crafted input. As a result, this could lead to unauthorized actions or data exposure, compromising the security of websites using affected versions up to 5.0.3. Website administrators should promptly assess and implement security measures to mitigate this threat.
Affected Version(s)
Contact Form 7 Dynamic Text Extension <= n/a