Stored Cross-Site Scripting in Contact Form 7 - Dynamic Text Extension Plugin by WordPress
CVE-2026-5116
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-5116?
The Contact Form 7 β Dynamic Text Extension plugin for WordPress contains a vulnerability that allows authenticated users with Editor-level access or higher to execute arbitrary web scripts. This occurs due to inadequate output escaping on form shortcode keys within the admin interface. Consequently, when an Administrator processes the scan feature for post meta and user data keys, malicious scripts may be executed, jeopardizing the security of the WordPress site.
Affected Version(s)
DTX β Dynamic Text Extension for Contact Form 7 0 <= 5.0.5