CVE Database /
CVE-2026-25863
CVE · High
CVE-2026-25863 — Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.7.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-25863
|
Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.7.3 |
Improper Validation of Specified Quantity in Input |
High
7.5
|
< 2.7.3
|
2.7.3 |
2026-05-04 |
—
|
CVE-2026-25863
The Conditional Fields for Contact Form 7 WordPress plugin has a vulnerability in its Wpcf7cfMailParser class. The hide_hidden_mail_fields_regex_callback method allows an attacker to specify an arbitrary integer value, which can cause an infinite loop of preg_replace operations, leading to excessive memory usage and potentially causing the server to crash. This vulnerability can be exploited by an unauthenticated attacker through the plugin's REST API endpoint.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings