# Contact Form 7 <= 6.1.7 - Authenticated (Editor+) Sensitive Information Exposure via User-Related Special Mail-Tags

- **ID:** WPSEC-2026-0484
- **Plugin:** Contact Form 7 (`contact-form-7`), https://wordpress.org/plugins/contact-form-7/
- **Affected versions:** all versions before 6.2
- **Fixed in:** 6.2 (Update to 6.2 or later.)
- **Severity:** Medium 4.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/contact-form-7
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0484/

## Description

The Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure via user-related special mail-tags in all versions up to, and including, 6.1.7. This is due to the plugin accepting any mail-tag name beginning with '_user_' and mapping it to an arbitrary WP_User property or user meta key. This makes it possible for authenticated attackers with Editor-level access or above, or any role allowed to edit contact forms, to place tags such as [_user_user_pass] or arbitrary user meta keys in a form's mail template. When a logged-in user such as an administrator submits that form, the attacker receives that user's password hash or other private user meta by email.

## References

- https://wpsec.com/vuln/WPSEC-2026-0484/
- https://plugins.svn.wordpress.org/contact-form-7/tags/6.2/
- https://wordpress.org/plugins/contact-form-7/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0484/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
