VendorsRock Lobster,contact_form_7any version
Vulnerabilities

Rock Lobster, LLC Contact Form any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-35489
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
Published 2020-12-17 · Modified
10.0EPSS 0.893
CVE-2018-20979
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
Published 2019-08-22 · Modified
9.8EPSS 0.020
CVE-2021-24159
Contact Form 7 Style <= 3.1.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Published 2021-04-05 · Modified
8.8EPSS 0.006
CVE-2023-6449
Contact Form 7 <= 5.8.3 - Authenticated (Editor+) Arbitrary File Upload
Published 2023-12-01 · Modified
7.2EPSS 0.017
CVE-2024-2242
Contact Form 7 <= 5.9 - Reflected Cross-Site Scripting
Published 2024-03-13 · Modified
6.1EPSS 0.013
CVE-2024-4704
Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect
Published 2024-06-27 · Modified
6.1EPSS 0.004
CVE-2025-3247
Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
Published 2025-04-16 · Analyzed
5.3EPSS 0.002
CVE-2014-2265
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
Published 2014-03-14 · Modified
5.0EPSS 0.031
CVE-2023-6630
Contact Form 7 – Dynamic Text Extension <= 4.1.0 - Insecure Direct Object Reference
Published 2024-01-11 · Modified
4.3EPSS 0.003