PT-2026-50635 · WordPress · Cf7 To Webhook

·

CVE-2026-11395

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CF7 to Webhook versions prior to 5.0.1
Description The CF7 to Webhook plugin for WordPress is subject to Server-Side Request Forgery (SSRF), a flaw where an attacker can induce the server-side application to make requests to an unintended location. This occurs via the pull the trigger function. Unauthenticated attackers can make web requests to arbitrary locations from the web application to query or modify information from internal services. Exploitation is possible if the admin-configured webhook URL contains a Contact Form 7 field placeholder in the host segment of the URL and the affected form is publicly accessible.
Recommendations Update the plugin to a version later than 5.0.0.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11395

Affected Products

Cf7 To Webhook