Conditional Fields for Contact Form 7 <= 2.7.2 - Unauthenticated Denial of Service
2026-05-04 00:00
Rahul KarneStrategic Overview
StatusPatched in 2.7.3
Affected PluginConditional Fields for Contact Form 7
Affected Version
<= 2.7.2CVSS5.3Medium
CVE
CVE-2026-25863Vulnerability Overview
The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.7.2. This makes it possible for unauthenticated attackers to starve the server of resources.
Technical Analysis
REMEDIATION: Update to version 2.7.3, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C