CVE-2024-10084: Sevenspark Contact Form 7 - Dynamic Text Extension

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.

Affected products

  • Sevenspark Contact Form 7 - Dynamic Text Extension: before 4.5.1 (fixed in 4.5.1)

Published 2024-11-05. Last modified 2026-06-17.