Contact Form 7 <= 6.1.7 - Authenticated (Editor+) Sensitive Information Exposure via User-Related Special Mail-Tags
- ID
- WPSEC-2026-0484
- Plugin
- Contact Form 7 (contact-form-7)
- Affected
- all versions before 6.2
- Remediation
- Update to 6.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-06
- Attack surface
- Contact Form 7 on WPSec AttackSurface
- Fix released
- Published
Description
The Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure via user-related special mail-tags in all versions up to, and including, 6.1.7. This is due to the plugin accepting any mail-tag name beginning with '_user_' and mapping it to an arbitrary WP_User property or user meta key. This makes it possible for authenticated attackers with Editor-level access or above, or any role allowed to edit contact forms, to place tags such as [_user_user_pass] or arbitrary user meta keys in a form's mail template. When a logged-in user such as an administrator submits that form, the attacker receives that user's password hash or other private user meta by email.
References
- https://wpsec.com/vuln/WPSEC-2026-0484/
- https://plugins.svn.wordpress.org/contact-form-7/tags/6.2/
- https://wordpress.org/plugins/contact-form-7/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS