PT-2026-36894 · WordPress · Conditional Fields For Contact Form 7
Rahul Karne
+1
·
Published
2026-05-04
·
Updated
2026-05-04
·
CVE-2026-25863
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Conditional Fields for Contact Form 7 WordPress plugin versions prior to 2.6.8
Description
An uncontrolled resource consumption issue exists in the
Wpcf7cfMailParser class. The hide hidden mail fields regex callback() method processes an iteration count from user-supplied POST parameters without validation or upper bound enforcement. Unauthenticated attackers can send an arbitrarily large integer via a REST API endpoint to trigger an unbounded loop with multiple preg replace() operations, leading to server memory exhaustion and PHP process crashes.Recommendations
Update the plugin to version 2.6.8 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conditional Fields For Contact Form 7