← WordPress Vulnerabilities
WordPress security by component

CF7 to Webhook

CF7 to Webhook is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 18, 2026; the highest published CVSS base score is 7.2.

Plugin slug: cf7-to-zapier

CVE-2026-11395: CF7 to Webhook: Server-side request forgery

CF7 to Webhook is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 5.0.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 18, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for cf7-to-zapier
Safe version
Jun 18, 2026 CVE-2026-11395
CF7 to Webhook: Server-side request forgery
CF7 to Webhook is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 5.0.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.2
NVDPending