CVE-2026-62043
Received Received - Intake

Unauthenticated Sensitive Data Exposure in Contact Form 7 Dynamic Text Extension

Vulnerability report for CVE-2026-62043, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Patchstack

Description

Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sevenspark Contact Form 7 – Dynamic Text Extension n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated sensitive data exposure in the Contact Form 7 – Dynamic Text Extension plugin for WordPress, affecting versions 5.0.7 and below. It allows attackers to access and steal private information such as passwords, emails, or payment details from vulnerable websites without needing authentication.

Detection Guidance

Check if the Contact Form 7 – Dynamic Text Extension plugin version 5.0.7 or below is installed on your WordPress site. Inspect server logs for unusual data exposure requests or unauthorized access patterns targeting form submissions.

Impact Analysis

Attackers could exploit this to steal sensitive user data, including passwords, emails, or payment details, leading to potential identity theft, financial loss, or unauthorized account access. The high CVSS score of 7.5 indicates a significant risk of widespread exploitation.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized exposure of personal and sensitive data. Organizations may face legal penalties, fines, or reputational damage if user data is compromised through this flaw.

Mitigation Strategies

Disable the Contact Form 7 – Dynamic Text Extension plugin immediately if installed. Apply Patchstack's mitigation rule if available. Update to the latest plugin version once an official patch is released. Consider seeking help from a hosting provider or web developer for secure removal or updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62043. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart