PLUGIN SECURITY
Is Contact Form 7 Dynamic Text Extension safe?
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
What this plugin does
- Slug:
contact-form-7-dynamic-text-extension - Author: sevenspark
- 100000+ active installs
- 94/100 rating (99 reviews on wordpress.org)
- 2043941 all-time downloads
- On WordPress.org since 2010-10-11
autofillcontact form 7dynamic formform fieldprepopulate
Maintenance status
- Last updated: 2026-08-04 1:53am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
5 known CVEs on file for Contact Form 7 Dynamic Text Extension.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-5116 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 5.0.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 5.0.6 | 5.0.6 | 2026-08-04 | — |
| CVE-2025-63068 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.5 (unfixed) | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 5.3 | < 5.0.5 | 5.0.5 | 2025-09-26 | — |
| CVE-2024-56218 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 5.0.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 5.0.2 | 5.0.2 | 2024-12-19 | — |
| CVE-2024-10084 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 4.5.1 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 4.5.1 | 4.5.1 | 2024-11-05 | — |
| CVE-2023-6630 | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 4.2.0 | Exposure of Private Personal Information to an Unauthorized Actor | Medium 4.3 | < 4.2.0 | 4.2.0 | 2024-01-10 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 3.0.0 | — | Unknown | < 3.0.0 | 3.0.0 | 2023-01-20 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 3.0.0 | — | Unknown | < 3.0.0 | 3.0.0 | 2023-01-19 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | 2019-07-26 | — |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | 2019-07-24 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] <= 5.0.3 (unfixed) | — | Unknown | < 5.0.3 | 5.0.3 | 0000-00-00 | — |
| — | DTX – Dynamic Text Extension for Contact Form 7 [contact-form-7-dynamic-text-extension] < 2.0.3 | — | Unknown | < 2.0.3 | 2.0.3 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Database Addon for Contact Form 7 – CFDB7 — 600000+ active installs — 100/100 (1875) — max PHP 8.4
- Redirection for Contact Form 7 — 200000+ active installs — 94/100 (275) — max PHP 8.4
- ReCaptcha v2 for Contact Form 7 — 200000+ active installs — 100/100 (89) — max PHP 8.4
- Conditional Fields for Contact Form 7 — 100000+ active installs — 96/100 (166) — max PHP 8.4
- LukasApps CAPTCHA tools for Contact Form 7 — 100000+ active installs — 82/100 (48)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.