Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32897 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own. |
Fri, 11 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sevenspark
Sevenspark contact Form 7 - Dynamic Text Extension |
|
| CPEs | cpe:2.3:a:sevenspark:contact_form_7_-_dynamic_text_extension:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Sevenspark
Sevenspark contact Form 7 - Dynamic Text Extension |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 05 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Nov 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own. | |
| Title | Contact Form 7 – Dynamic Text Extension <= 4.5 - Information Disclosure via Shortcode | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:28:41.027Z
Reserved: 2024-10-17T14:12:04.835Z
Link: CVE-2024-10084
Updated: 2024-11-05T21:44:06.298Z
Status : Analyzed
Published: 2024-11-05T22:15:20.680
Modified: 2025-07-11T13:57:29.007
Link: CVE-2024-10084
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:06:28Z
EUVD