Web Application Vulnerability in Contact Form 7 Dynamic Text Extension by SevenSpark
CVE-2025-63068
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-63068?
The Contact Form 7 Dynamic Text Extension plugin for WordPress is susceptible to a vulnerability that allows for improper neutralization of script-related HTML tags. This flaw enables attackers to inject malicious code into web pages via crafted input. As a result, this could lead to unauthorized actions or data exposure, compromising the security of websites using affected versions up to 5.0.3. Website administrators should promptly assess and implement security measures to mitigate this threat.
Affected Version(s)
Contact Form 7 Dynamic Text Extension <= n/a
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Najib Sinjari | Patchstack Bug Bounty Program