The “Contact Form 7 – Repeatable Fields” plugin, a popular extension for WordPress, was recently found to have a security flaw. This vulnerability, known as Stored Cross-Site Scripting (XSS), could allow certain users to inject malicious code into your website. If you use this plugin, it’s important to understand the risk and take action.
When a website is vulnerable to Stored XSS, it means that malicious code can be permanently saved on the server. Later, when other users visit the affected pages, this malicious code will automatically run in their web browsers. For this particular vulnerability, an attacker would need to be an authenticated user with at least contributor-level access to your WordPress site. Once exploited, this could lead to various issues, such as defacing your website, redirecting visitors to malicious sites, or stealing sensitive information from users.
CVE Details
- CVE ID: CVE-2024-10180
- Product: Contact Form 7 – Repeatable Fields plugin for WordPress
- Published Date: October 24, 2024
- Severity: Medium (CVSS: 6.4)
- Status: Analyzed
Affected Products
This Stored Cross-Site Scripting (XSS) vulnerability impacts all versions of the Contact Form 7 – Repeatable Fields plugin up to, and including, version 2.0.1. If you are running any version within this range, your website is potentially at risk.
Current Status
As of December 12, 2025, the vulnerability status is “Analyzed,” meaning it has been thoroughly investigated and understood by security researchers and the vendor. A fix has been released to address this issue.
Severity Level
The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 6.4, classifying it as Medium severity. While not critical, a medium-severity vulnerability still poses a significant risk. It means that exploitation is possible, and the potential impact could be considerable, especially if an attacker already has some level of access to your WordPress site. Users with roles like ‘contributor’ or higher could potentially leverage this flaw.
Possible Solutions
The good news is that a patch is available. To secure your WordPress website and protect your users from this Stored XSS vulnerability, you must update the Contact Form 7 – Repeatable Fields plugin to version 2.0.2 or later.
This security release, published on October 22, 2024, specifically addresses the insufficient input sanitization and output escaping issues within the plugin’s field_group shortcode. Updating your plugin is crucial and should be done as soon as possible.
How to Update Your Plugin:
- Log in to your WordPress admin dashboard.
- Navigate to ‘Plugins’ > ‘Installed Plugins’.
- Locate “Contact Form 7 – Repeatable Fields” in the list.
- If an update to version 2.0.2 or higher is available, click the “Update Now” link.
- Always back up your website before performing any updates.
Staying vigilant with plugin updates is a fundamental practice in maintaining a secure WordPress environment.
References
https://plugins.trac.wordpress.org/changeset/3173935/
https://wordpress.org/plugins/cf7-repeatable-fields/#developers
https://www.wordfence.com/threat-intel/vulnerabilities/id/0782bc16-7d21-4205-af01-97e3ad3db40b?source=cve


