Executive brief
CF7 WOW Styler is a WordPress plugin used to customize the appearance of Contact Form 7 forms. A security flaw in the plugin allows unauthorized individuals to bypass access controls and potentially modify settings or perform actions intended only for administrators. This could lead to unauthorized changes to the website's form styles or configuration, though it does not directly expose sensitive customer data.
Technical details
The CF7 WOW Styler plugin for WordPress is vulnerable to a Broken Access Control (Missing Authorization) vulnerability in versions up to and including 1.7.6. The flaw stems from a failure to implement proper authorization checks or nonce validation on certain functions, allowing unauthenticated attackers to execute actions that should be restricted to higher-privileged users. An attacker can exploit this over the network without any user interaction. The vulnerability is classified as CWE-862 (Missing Authorization). A patch is available in version 1.8.5.
Affected products
- Tobias CF7 WOW Styler <= 1.7.6
Timeline
- 2025-11-14: other: Reported by Rapid0nion
- 2026-05-21: disclosed: Early warning sent to Patchstack customers
- 2026-05-21: advisory: Published by Patchstack and NVD
- 2026-05-21: patched: Patch available in version 1.8.5