CVE-2026-62058: Wpexperts CF7 Apps

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.

Affected products

  • Wpexperts CF7 Apps: up to and including 3.7.2

Published 2026-10-01. Last modified 2026-10-01.