CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Security & Risk Analysis

wordpress.org/plugins/cf7-submissions

Securely Store and Manage CF7 Submissions Hassle-Free

2K active installs v0.26 PHP 7.4+ WP 6.0+ Updated Jun 3, 2025
contact-formcontact-form-7contact-form-7-entriescontact-form-7-messagescontact-form-7-submissions
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Safe to Use in 2026?

Mostly Safe

Score 78/100

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 10mo ago
Risk Assessment

The "cf7-submissions" plugin v0.26 exhibits a generally good security posture based on the static analysis. It demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The absence of critical or high severity taint flows further suggests that sensitive data is handled with care. The plugin also incorporates a reasonable number of nonce and capability checks, contributing to its defensibility against common web attacks.

However, a significant concern arises from the plugin's vulnerability history, which shows one known medium severity CVE that is currently unpatched. The common vulnerability type listed as "Missing Authorization" in past incidents, even if this specific unpatched CVE is not directly related, indicates a historical pattern that warrants caution. While the current static analysis doesn't reveal obvious entry points without authentication, the past trend of authorization issues means that the unpatched CVE could potentially be exploited by unauthorized users.

In conclusion, while the code itself appears robust with good practices in place for SQL and output handling, the presence of an unpatched medium severity vulnerability and a history of authorization issues presents a notable risk. Users should be aware of this outstanding vulnerability and its potential implications, especially given the plugin's past security challenges.

Key Concerns

  • Unpatched medium severity CVE
  • History of missing authorization vulnerabilities
Vulnerabilities
1

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58016medium · 5.4Missing Authorization

CF7 Submissions <= 0.26 - Missing Authorization

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
64 escaped
Nonce Checks
8
Capability Checks
5
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped64 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<single> (views\submissions\single.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Attack Surface

Entry Points0
Unprotected0

Scheduled Events 1

codexpert-daily
Maintenance & Trust

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 3, 2025
PHP min version7.4
Downloads16K

Community Trust

Rating80/100
Number of ratings4
Active installs2K
Developer Profile

CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Developer Profile

Codexpert, Inc

10 plugins · 41K total installs

75
trust score
Avg Security Score
81/100
Avg Patch Time
39 days
View full developer profile
Detection Fingerprints

How We Detect CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-submissions/assets/css/chosen.min.css/wp-content/plugins/cf7-submissions/assets/js/chosen.jquery.min.js/wp-content/plugins/cf7-submissions/assets/css/admin.css/wp-content/plugins/cf7-submissions/assets/js/admin.js/wp-content/plugins/cf7-submissions/assets/js/custom.js/wp-content/plugins/cf7-submissions/assets/css/custom.css
Script Paths
/wp-content/plugins/cf7-submissions/assets/js/chosen.jquery.min.js/wp-content/plugins/cf7-submissions/assets/js/admin.js/wp-content/plugins/cf7-submissions/assets/js/custom.js
Version Parameters
cf7-submissions/assets/css/chosen.min.css?ver=cf7-submissions/assets/js/chosen.jquery.min.js?ver=cf7-submissions/assets/css/admin.css?ver=cf7-submissions/assets/js/admin.js?ver=cf7-submissions/assets/js/custom.js?ver=cf7-submissions/assets/css/custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
cf7s-deletecf7s-restorecf7s-readcf7s-unreadcf7s-bulk-actionscf7s-contact-formcf7s-submision-idcf7s-submission-date+11 more
HTML Comments
<!-- cf7-submissions --><!-- .cf7-submissions --><!-- END .cf7-submissions --><!-- CF7 Submissions -->+3 more
Data Attributes
data-cf7s-iddata-cf7s-actiondata-cf7s-noncedata-cf7s-modal-target
JS Globals
cf7s_localizecf7_submissions_params
REST Endpoints
/wp-json/cf7s/v1/submissions
FAQ

Frequently Asked Questions about CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more