VYPR

CF7 to Webhook

by WordPress

CVEs (1)

  • CVE-2026-11395HigJun 18, 2026
    risk 0.47cvss 7.2epss 0.00

    The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_trigger. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…