CVE-2025-13146 | sevenspark Contact Form 7 Plugin up to 5.0.6 on WordPress Dynamic Text Extension do_shortcode code injection
A vulnerability was found in sevenspark Contact Form 7 Plugin up to 5.0.6 on WordPress. It has been classified as critical. This impacts the function do_shortcode of the component Dynamic Text Extension. This manipulation causes code injection.
This vulnerability appears as CVE-2025-13146. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More