CVE-2026-62058: WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability
Published Oct 1, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.
Affected Software
1 affected component
Wpexperts CF7 Apps<=3.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CF7 Apps pluginto a version that resolves this vulnerability.Fixed in 3.8.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed over the network with low attack complexity. It does not require privileges or user interaction.
2
What is the expected security impact?
The reported impact is limited to confidentiality, with a low confidentiality impact. No integrity or availability impact is indicated.