CVE · High

CVE-2026-25863 — Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-25863 Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.7.3 Improper Validation of Specified Quantity in Input High 7.5 < 2.7.3 2.7.3 2026-05-04

CVE-2026-25863

The Conditional Fields for Contact Form 7 WordPress plugin has a vulnerability in its Wpcf7cfMailParser class. The hide_hidden_mail_fields_regex_callback method allows an attacker to specify an arbitrary integer value, which can cause an infinite loop of preg_replace operations, leading to excessive memory usage and potentially causing the server to crash. This vulnerability can be exploited by an unauthenticated attacker through the plugin's REST API endpoint.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.