Medium 5.3 Unfixed
2025-12-09≤ 5.0.5
CVE-2025-63068
Minimum safe version
5.0.2
Update to 5.0.2 or later to address 8 fixable vulnerabilities
CVE-2025-63068
CVE-2024-56218
CVE-2024-10084
CVE-2023-6630
WordPress Contact Form 7 Dynamic Text Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
Contact Form 7 Dynamic Text Extension <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Contact Form 7 Dynamic Text Extension < 2.0.3 - Reflected Cross-Site Scripting
Contact Form 7 Dynamic Text Extension <= 2.0.2.1 - Reflected XSS
WordPress Contact Form 7 Dynamic Text Extension plugin <= 2.0.2.1 - Reflected Cross-Site Scripting (XSS) vulnerability