Contact Form 7

Vulnerabilities 12Slug contact-form-7Latest version 6.1.5WordPress.org →

Minimum safe version

6.0.6

Update to 6.0.6 or later to address 12 fixable vulnerabilities

Latest available6.1.5
Medium 5.3
2025-04-16< 6.0.6

WordPress Contact Form 7 Plugin <= 6.0.5 is vulnerable to Other Vulnerability Type

N/A
2014-08-01< 3.5.3

Contact Form 7 <= 3.5.2 - Arbitrary File Upload

N/A
< 3.5.3

Contact Form 7 &lt;= 3.5.2 - File Upload Remote Code Execution

N/A
2014-08-01< 3.5.3

WordPress Contact Form 7 Plugin <= 3.5.2 - Remote Code Execution

N/A
2018-09-13< 5.0.4

WordPress Contact Form 7 plugin <= 5.0.3 - Privilege Escalation vulnerability

N/A
2020-12-17< 5.3.2

WordPress Contact Form 7 plugin <= 5.3.1 - Unrestricted File Upload vulnerability