SMS Contact Form 7 Notifications by ClickSend
SMS Contact Form 7 Notifications by ClickSend has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for SMS Contact Form 7 Notifications by ClickSend has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Legion Hunter. SMS Contact Form 7 Notifications by ClickSend is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.0.
CVE-2025-62915SMS Contact Form 7 Notifications by ClickSend <= 1.4.0 - Missing Authorization
Read the full analysisVulnerability Records

SMS Contact Form 7 Notifications by ClickSend
Author
clicksend
Reliable and global SMS notifications for Contact Form 7. ClickSend brings instant SMS communication to the mix. By integrating these tools, you elevate your customer engagement. Imagine receiving an SMS notification the moment a user completes a form on your website – whether it’s a lead inquiry, feedback, or a contact form. This integration lets you set up real-time SMS alerts for form submissions, so you never miss an important interaction. Message customers as soon as they complete a form and tailor the SMS message to your business needs.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C