Junglewise Threat Intelligence

CVE-2025-13146: SevenSpark Contact Form 7 Dynamic Text Extension arbitrary shortcode execution

CVE-2025-13146 · Severity: medium · CVSS 6.5 · Published 2026-07-22

Executive brief

A vulnerability in the Contact Form 7 – Dynamic Text Extension plugin for WordPress allows unauthorized individuals to execute arbitrary shortcodes. This plugin is used to add dynamic content to contact forms, and an exploit could allow an attacker to access sensitive information or perform unauthorized actions on the website. The issue affects all versions of the plugin up to and including 5.0.6.

Technical details

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution due to the software failing to properly validate user-supplied input before passing it to the WordPress do_shortcode function. This vulnerability exists in all versions up to and including 5.0.6. An unauthenticated remote attacker can exploit this by triggering a specific action that processes the unvalidated input, allowing them to execute any shortcode available on the site. This can lead to information disclosure or other unauthorized actions depending on the shortcodes available in the environment. While a partial patch was introduced in version 5.0.4, the vulnerability was not fully addressed until after version 5.0.6.

Affected products

  • SevenSpark Contact Form 7 – Dynamic Text Extension up to, and including, 5.0.6

Timeline

  • 2026-07-22: disclosed: NVD publication date

References