WordPress · Contact Form 7 – Dynamic Text Extension · CVE-2026-5116
**Name of the Vulnerable Software and Affected Versions**
Contact Form 7 – Dynamic Text Extension versions prior to 5.0.6
**Description**
Stored Cross-Site Scripting occurs due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. Authenticated attackers with Editor-level access and above can inject arbitrary web scripts that execute when an Administrator runs the scan feature. Cross-Site Scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
Update to version 5.0.6 or later.