PLUGIN SECURITY
Is Contact Form 7 Dynamic Text Extension safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Contact Form 7 Dynamic Text Extension WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
- Slug:
contact-form-7-dynamic-text-extension
Maintenance status
Known vulnerabilities
5 known CVEs on file for Contact Form 7 Dynamic Text Extension.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-5116 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 5.0.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 5.0.6 | 5.0.6 | 2026-08-04 | — |
| CVE-2025-63068 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.5 (unfixed) | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 5.3 | < 5.0.5 | 5.0.5 | 2025-09-26 | — |
| CVE-2024-56218 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 5.0.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 5.0.2 | 5.0.2 | 2024-12-19 | — |
| CVE-2024-10084 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 4.5.1 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 4.5.1 | 4.5.1 | 2024-11-05 | — |
| CVE-2023-6630 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 4.2.0 | Exposure of Private Personal Information to an Unauthorized Actor | Medium 4.3 | < 4.2.0 | 4.2.0 | 2024-01-10 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 3.0.0 | — | Unknown | < 3.0.0 | 3.0.0 | 2023-01-20 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 3.0.0 | — | Unknown | < 3.0.0 | 3.0.0 | 2023-01-19 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | 2019-07-26 | — |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | 2019-07-24 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.3 (unfixed) | — | Unknown | < 5.0.3 | 5.0.3 | 0000-00-00 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.