Conditional Fields for Contact Form 7 <= 2.7.2 - Unauthenticated Denial of Service

2026-05-04 00:00
Rahul Karne

Strategic Overview

Status
Patched in 2.7.3
Affected Version<= 2.7.2
CVSS5.3Medium
CVECVE-2026-25863
View all Conditional Fields for Contact Form 7 vulnerabilities

Vulnerability Overview

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.7.2. This makes it possible for unauthenticated attackers to starve the server of resources.

Technical Analysis

REMEDIATION: Update to version 2.7.3, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

Conditional Fields for Contact Form 7 <= 2.7.2 - Unauthenticated Denial of Service (CVE-2026-25863)