CVE 8.7 HIGH

Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption_CVE-2026-25863

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or upper bound enforcement. Unauthenticated attackers can supply an arbitrarily large integer value through the REST API endpoint to cause unbounded loop execution with multiple preg_replace() operations, exhausting server memory and crashing the PHP process.

AI Analysis

Uncontrolled resource consumption vulnerability in Conditional Fields for Contact Form 7 WordPress plugin

Basic Information

ID CVE-2026-25863
Source VulnCheck
Published May 4, 2026 at 18:29

Affected Product

Vendor Jules Colle
Product Conditional Fields for Contact Form 7
Version 2.6.7
Affected Versions Jules Colle Conditional Fields for Contact Form 7 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Jules Colle
Product Conditional Fields for Contact Form 7
Version 2.6.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.