Vulnerabilities / Contact Form 7 / WPSEC-2026-0484

Contact Form 7 <= 6.1.7 - Authenticated (Editor+) Sensitive Information Exposure via User-Related Special Mail-Tags

Medium 4.5 CWE-200Fixed in 6.2
ID
WPSEC-2026-0484
Plugin
Contact Form 7 (contact-form-7)
Affected
all versions before 6.2
Remediation
Update to 6.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Weakness
CWE-200
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-06
Attack surface
Contact Form 7 on WPSec AttackSurface
Fix released
Published

Description

The Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure via user-related special mail-tags in all versions up to, and including, 6.1.7. This is due to the plugin accepting any mail-tag name beginning with '_user_' and mapping it to an arbitrary WP_User property or user meta key. This makes it possible for authenticated attackers with Editor-level access or above, or any role allowed to edit contact forms, to place tags such as [_user_user_pass] or arbitrary user meta keys in a form's mail template. When a logged-in user such as an administrator submits that form, the attacker receives that user's password hash or other private user meta by email.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0