CVE-2025-13146
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, a
CVSS
6.5
Medio
EPSS
0.5%
p38
KEV
—
Exploit Today
11
0-100
Publicado: 22 jul 2026 · Última mod.: 22 jul 2026 · CWE-94
Sin historial EPSS suficiente todavía.
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L765
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L782
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/includes/utilities.php#L265
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset/3430784/
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/3e5ad3a7-03c5-4085-b330-bc77e7e46cea?source=cve
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-648158.1 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files6hCVE-2026-648037.8 ALT—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK6hCVE-2026-648027.8 ALT—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration6hCVE-2026-595439.9 CRÍ—
——0Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.6hCVE-2026-150119.8 CRÍ57.7%
——17The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated attackers to invoke arbitrary parameterless PHP functions, which can be used to disrupt site functionality or expose sensitive information. The required nonce is publicly emitted via wp_localize_script whenever the plugin's [emd_form] shortcode is rendered on any public-facing page, making the endpoint reachable by unauthenticated visitors without any prior authentication or privilege.8hCVE-2026-166069.8 CRÍ63.2%
——19A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.21h