Junglewise Threat Intelligence

CVE-2026-11395: mariovalney CF7 to Webhook SSRF via pull_the_trigger

CVE-2026-11395 · Severity: high · CVSS 7.2 · Published 2026-06-18

Executive brief

The CF7 to Webhook plugin for WordPress, which connects contact forms to external services like Zapier, contains a security flaw that allows unauthorized individuals to send web requests from your server. This could be used by attackers to scan your internal network or access sensitive information from other services running on your infrastructure. The risk is highest if your contact forms are publicly accessible and configured to use dynamic placeholders in their webhook settings.

Technical details

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via the 'pull_the_trigger' function in all versions up to and including 5.0.0. The vulnerability occurs when an administrator configures a webhook URL that includes a Contact Form 7 field placeholder within the host segment of the URL. An unauthenticated attacker can exploit this by submitting a crafted value through a publicly accessible contact form, causing the web server to initiate requests to arbitrary internal or external locations. This can lead to internal port scanning or unauthorized interaction with internal services. A patch appears to be available in newer versions as indicated by the developer's changeset.

Affected products

  • mariovalney CF7 to Webhook (CF7 to Zapier) up to, and including, 5.0.0

Timeline

  • 2026-06-18: disclosed: Initial publication of the CVE record.
  • 2026-06-18: advisory: Wordfence published detailed vulnerability information.

References