Contact Form to Any API
Contact Form to Any API has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.9 out of 10. Severity breakdown: 1 critical and 3 high. 2026 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (43%). Other recurring categories include SQL Injection, Exposure Of Sensitive Information To An Unauthorized Actor.
Every one of the 7 issues recorded for Contact Form to Any API has a vendor fix available, so running the current release closes all known holes.
6 independent researchers contributed these findings, most of them (2) reported by Arvandy. Contact Form to Any API is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-30242Contact Form to Any API <= 1.1.8 - Authenticated (Subscriber+) SQL Injection
Read the full analysisVulnerability Records

Contact Form to Any API
Author
IT Path Solutions
contact-form-7Contact Form 7 to Any API lets you send form submissions directly to any CRM, Webhook, marketing platform or REST API with complete control over payloads, endpoints, headers and authentication. Built for developers, agencies, and technical teams who need flexible, secure WordPress API and Webhook integrations without extra middleware. All data stays private within WordPress until it’s successfully sent to your chosen API. Video Demo: Key Features Send CF7 Leads to Remote API’s such as CRM and other External API using POST/GET Create up to 5 API Connections Supports Simple & Fixed Format of JSON Supports Basic Auth Supports Bearer Auth API Logs Management with submitted data and API response Auto Delete Logs (purge logs older than configurable number of days) Email Notifications on API Failure Save Contact Form 7 form submitted data to the database Export Contact Form 7 Data in CSV, EXCEL, PDF, Print Single Or Multiple delete CF7 entries Conditional Field Support (Equals / Not Equals) File input supported – Uploaded file will convert into BASE64 and send to API Multisite Compatible WPML Compatible Predefined Tags support Send data to multiple API (PRO) Support Multi Level or Any Format of JSON (PRO) Send attachments to any API (PRO) Option to Choose when to send data to API – Before CF7 mail sent OR After mail sent (PRO) Multi File Upload Support (PRO) Compatible with Multiline files upload for contact form 7 Plugin (PRO) Option to choose Numerical Fields / Integer Fields (PRO) Option to choose Multiple File upload fields (PRO) Retry Failed API Logs (Auto and Manual Retry) (PRO) Bulk Retry failed API calls (PRO) Advanced Email Notifications on API Failure (PRO) Priority Support (PRO) Paid plugin customization support for JWT Token Integration with Any API (Contact us) Paid plugin customization support for OAuth 2.0 API Integration (Contact us) Paid Plugin customization support for any API (Contact us) WPForms to Any API Plugin – (Plugin for WPForm Users – Connect WPForm to Any API) Upgrade to PRO for Advanced Integrations Unlock advanced flexibility and full control with Contact Form 7 to Any API PRO Unlimited API Connections per site Multi-level / Any JSON Structure support Multiple File Upload Field Support Define Integer Fields – map numeric fields precisely Retry Failed API Logs – auto and manually retry any failed API call directly from the log screen Bulk Retry – re-send multiple failed API calls at once with a single click Advanced Email Notifications on API Failure – send failure alerts to multiple recipients Priority Support for faster assistance Price: $29.99/year Upgrade to PRO Optional OAuth 2.0 and JWT PRO Add-On For APIs that require advanced authorization, our PRO Add-On ($99.99) provides: OAuth 2.0 and JWT token authentication Automatic access/refresh token management JWT Token Integration with Any API Perfect for enterprise or expiring token setups Get the Add-On Set Your Own Header Request Parameters Define custom header parameters to match your integration requirements. Examples: Authorization: MY_API_KEY Authorization: Bearer xxxxxxx Authorization: Basic xxxxxxx Content-Type: application/json Basic and Bearer authentication can be configured directly in the header input fields. Supported CRMs and APIs Connect Contact Form 7 with 200+ CRM and marketing platforms: Twilio WhatsApp — Watch Video Brevo — Watch Video Mailcoach — Watch Video Pipeline CRM — Watch Video Mailchimp — Watch Video Mailbluster — Watch Video Zapier — Watch Video HubSpot CRM — Watch Video Salesforce CRM Pipedrive — Watch Video Freshsales — Watch Video Airtable — Watch Video Capsule — Watch Video EngageBay — Watch Video OnePage CRM Clio Grow — Watch Video Close CRM — Watch Video Systeme CRM — Watch Video Insightly CRM — Watch Video Twenty CRM — Watch Video Agile CRM — Watch Video Sage CRM Odoo CRM/ERP System Fluent CRM Lead Post API Virtuagym API Pilotsolution OS Ticket Samdock CRM Mikrowisp Bats CRM FRS Labs API Get Cobra by ArcaMax Network Worldfilia SingleOps GorillaDesk API Sembark API Superoffice CRM Flowdesk JobAdder Unlatch CRM Mail2many Workato Jetbrains / Intellij Space API Fincenfetch Lead Docket Agendor API Lead IM Israel Personio Kala CRM Israel Pixxicrm easybizy sell.do Events500 SendPulse CRM And many more Browse all integration guides: Blog | Video Tutorials Our Other Plugins WPForm to Any API WPForm to Any API is most powerful plugin to send WPForm data to any third party services. It can be use to send data to CRM Or any REST API. Easy to use and User friendly settings Support Contact Form 7 to Any API is developed and supported by IT Path Solutions. If you have questions or encounter issues, visit our Support Forum or contact support@contactformtoapi.com. Your feedback helps us improve and expand this plugin for the entire WordPress community. We also welcome: Bug and documentation reports Feature suggestions Translation contributions How You Can Support WordPress grows through community, and your help makes a difference. Report Bugs or Issues: Found a problem? Report it using the official guide. Fix or Suggest Docs Updates: Share corrections or suggestions on the Support Forum. Report Security Concerns: Follow the WordPress Security Reporting Guide. Suggest Features or Improvements: Have ideas? Submit them here. Contribute to Translations: Help translate the plugin on WordPress Translate. Explore our other plugins or visit WordPress Gems to check out what we do. License This plugin is licensed under the GNU General Public License v2 or later. https://www.gnu.org/licenses/gpl-2.0.html
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C