Web Application Vulnerability in Contact Form 7 Dynamic Text Extension by SevenSpark
CVE-2025-63068
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63068?
The Contact Form 7 Dynamic Text Extension plugin for WordPress is susceptible to a vulnerability that allows for improper neutralization of script-related HTML tags. This flaw enables attackers to inject malicious code into web pages via crafted input. As a result, this could lead to unauthorized actions or data exposure, compromising the security of websites using affected versions up to 5.0.3. Website administrators should promptly assess and implement security measures to mitigate this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form 7 Dynamic Text Extension <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved