Connect Contact Form 7 and AWeber Security & Risk Analysis

wordpress.org/plugins/integrate-contact-form-7-and-aweber

Integrate AWeber mailing lists with Contact Form 7. Automatically add form subscribers to your AWeber lists.

300 active installs v026.02.10.1905 PHP 7.4+ WP 6.4+ Updated Mar 2, 2026
awebercontact-form-7email-marketingmailing-listnewsletter
98
A · Safe
CVEs total2
Unpatched0
Last CVENov 7, 2025
Safety Verdict

Is Connect Contact Form 7 and AWeber Safe to Use in 2026?

Generally Safe

Score 98/100

Connect Contact Form 7 and AWeber has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Nov 7, 2025Updated 1mo ago
Risk Assessment

The 'integrate-contact-form-7-and-aweber' plugin exhibits a generally positive security posture, with a strong emphasis on output escaping and a low number of external HTTP requests. The absence of critical or high-severity taint flows, along with no reported unpatched CVEs, is also a good sign. However, the static analysis reveals several areas that warrant caution. The plugin lacks nonce checks entirely, which is a significant oversight for protecting against CSRF attacks, especially with numerous cron events. While there are capability checks, the complete absence of checks on AJAX handlers and REST API routes, coupled with the lack of explicit authorization checks on some code paths, presents a potential entry point for unauthorized actions if these components were to be exposed or if permissions are not strictly managed at a higher level.

The vulnerability history shows two medium-severity CVEs, both related to Missing Authorization. This pattern suggests a recurring weakness in how the plugin handles user permissions. While there are currently no unpatched vulnerabilities, this history indicates a need for vigilant monitoring and prompt patching of future discoveries. The plugin has a moderate number of cron events, and without proper authorization checks on these, they could become a vector for attacks. In conclusion, while the plugin demonstrates good practices in many areas, the lack of comprehensive authorization checks on its entry points, particularly AJAX and REST API routes, and the absence of nonce checks are notable weaknesses that could be exploited.

Key Concerns

  • No nonce checks present
  • 2 medium CVEs related to Missing Authorization
  • No authorization checks on AJAX handlers
  • No permission callbacks on REST API routes
  • SQL queries not always using prepared statements
  • Some output not properly escaped
Vulnerabilities
2

Connect Contact Form 7 and AWeber Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-12167medium · 4.3Missing Authorization

Contact Form 7 AWeber Extension <= 0.1.42 - Missing Authorization to Authenticated (Subscriber+) Log Reset

Nov 7, 2025 Patched in 0.1.43 (1d)
CVE-2025-49988medium · 5.3Missing Authorization

Contact Form 7 AWeber Extension <= 0.1.42 - Missing Authorization

Jun 19, 2025 Patched in 0.1.43 (142d)
Code Analysis
Analyzed Mar 16, 2026

Connect Contact Form 7 and AWeber Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
5 prepared
Unescaped Output
15
162 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

63% prepared8 total queries

Output Escaping

92% escaped177 total outputs
Attack Surface

Connect Contact Form 7 and AWeber Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionplugins_loadedcf7-awb-ext.php:32
actionadmin_print_scriptsincludes\admin\class-icf7a-admin-assets.php:40
filterwpcf7_ajax_loaderincludes\admin\class-icf7a-admin-assets.php:41
filteradmin_body_classincludes\admin\class-icf7a-admin-assets.php:42
actionadmin_bar_menuincludes\admin\class-icf7a-admin-bar.php:37
actionwp_enqueue_scriptsincludes\admin\class-icf7a-admin-bar.php:38
actionadmin_enqueue_scriptsincludes\admin\class-icf7a-admin-bar.php:39
actionadmin_footerincludes\admin\class-icf7a-admin-bar.php:40
actionwp_footerincludes\admin\class-icf7a-admin-bar.php:41
actionadmin_initincludes\class-icf7a-bootstrap.php:308
actioncmatic_weekly_telemetryincludes\class-icf7a-bootstrap.php:309
filtercron_schedulesincludes\class-icf7a-bootstrap.php:349
filterwpcf7_editor_panelsincludes\controllers\class-icf7a-form-panel-controller.php:155
actionwpcf7_admin_footerincludes\controllers\class-icf7a-form-panel-controller.php:156
filterwpcf7_form_class_attrincludes\controllers\class-icf7a-form-panel-controller.php:157
filterwpcf7_form_action_urlincludes\controllers\class-icf7a-form-panel-controller.php:160
actionadmin_noticesincludes\core\class-icf7a-activator.php:58
actionadmin_initincludes\core\class-icf7a-activator.php:59
actionafter_setup_themeincludes\core\class-icf7a-activator.php:60
actionwpcf7_after_saveincludes\core\class-icf7a-form-settings.php:64
actionadmin_initincludes\core\class-icf7a-migration.php:60
actionadmin_initincludes\core\class-icf7a-options-consolidation.php:116
actionadmin_initincludes\core\class-icf7a-per-form-consolidation.php:112
filterauto_update_pluginincludes\core\class-icf7a-wordpress.php:47
actionrest_api_initincludes\rest\class-icf7a-rest-controller.php:145
actionwpcf7_before_send_mailincludes\services\class-icf7a-subscriber.php:54
filtercron_schedulesincludes\signals\class-icf7a-signals-scheduler.php:108
actioncmatic_metrics_heartbeatincludes\signals\class-icf7a-signals-scheduler.php:109
actionadmin_initincludes\signals\class-icf7a-signals-scheduler.php:110
actionicf7a_subscription_successincludes\signals\class-icf7a-signals-scheduler.php:113
actionicf7a_on_activationincludes\signals\class-icf7a-signals-tracker.php:60
actionicf7a_on_deactivationincludes\signals\class-icf7a-signals-tracker.php:61

Scheduled Events 15

cmatic_weekly_telemetry
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
cmatic_metrics_heartbeat
Maintenance & Trust

Connect Contact Form 7 and AWeber Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version7.4
Downloads54K

Community Trust

Rating50/100
Number of ratings8
Active installs300
Developer Profile

Connect Contact Form 7 and AWeber Developer Profile

Renzo Johnson

5 plugins · 51K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
346 days
View full developer profile
Detection Fingerprints

How We Detect Connect Contact Form 7 and AWeber

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrate-contact-form-7-and-aweber/assets/css/aweber-lite.css/wp-content/plugins/integrate-contact-form-7-and-aweber/assets/js/aweber-lite.js/wp-content/plugins/integrate-contact-form-7-and-aweber/assets/images/fading-squares.gif
Script Paths
/wp-content/plugins/integrate-contact-form-7-and-aweber/assets/js/aweber-lite.js
Version Parameters
integrate-contact-form-7-and-aweber/cf7-awb-ext.phpaweber-pro/aweber-pro.php

HTML / DOM Fingerprints

CSS Classes
vcawb-litevcawb
JS Globals
vcawb_ajax_data
REST Endpoints
/vcawb/v1/
FAQ

Frequently Asked Questions about Connect Contact Form 7 and AWeber