WP Clinic
Log in Sign up

CVE · High

CVE-2026-25863 — Conditional Fields for Contact Form 7 [cf7-conditional-fields] <= 2.6.7 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-25863 Conditional Fields for Contact Form 7 [cf7-conditional-fields] <= 2.6.7 (unfixed) Improper Validation of Specified Quantity in Input High 7.5 < 2.6.7 2.6.7 2026-05-04

CVE-2026-25863

Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or upper bound enforcement. Unauthenticated attackers can supply an arbitrarily large integer value through the REST API endpoint to cause unbounded loop execution with multiple preg_replace() operations, exhausting server memory and crashing the PHP process.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.