Stored Cross-Site Scripting in Contact Form 7 - Dynamic Text Extension Plugin by WordPress
CVE-2026-5116

4.4MEDIUM

What is CVE-2026-5116?

The Contact Form 7 – Dynamic Text Extension plugin for WordPress contains a vulnerability that allows authenticated users with Editor-level access or higher to execute arbitrary web scripts. This occurs due to inadequate output escaping on form shortcode keys within the admin interface. Consequently, when an Administrator processes the scan feature for post meta and user data keys, malicious scripts may be executed, jeopardizing the security of the WordPress site.

Affected Version(s)

DTX – Dynamic Text Extension for Contact Form 7 0 <= 5.0.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SATYARTH PRAKASH (XoxoL33t)
.