Executive brief
Aurovrata Venet Post My CF7 Form, a WordPress plugin used to map Contact Form 7 submissions to custom post types, contains a security flaw that allows unauthorized users to perform restricted actions. An unauthenticated attacker could exploit this to modify website content or settings without permission. This could lead to unauthorized data modification and potential disruption of website operations.
Technical details
A broken access control vulnerability exists in the Post My CF7 Form plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. The flaw allows an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the attack is low complexity and requires no user interaction, primarily impacting the integrity of the system. The vulnerability is addressed in version 7.0.0.
Affected products
- Aurovrata Venet Post My CF7 Form <= 6.2.0
Timeline
- 2026-05-16: other: Reported by researcher Mitchell
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: NVD publication date