CVE-2026-25863 | Jules Colle Conditional Fields for Contact Form 7 up to 2.7.2 on WordPress REST API Endpoint hide_hidden_mail_fields_regex_callback improper validation of specified quantity in input (EUVD-2026-27083)
A vulnerability was found in Jules Colle Conditional Fields for Contact Form 7 up to 2.7.2 on WordPress. It has been classified as problematic. This affects the function hide_hidden_mail_fields_regex_callback of the component REST API Endpoint. The manipulation leads to improper validation of specified quantity in input.
This vulnerability is referenced as CVE-2026-25863. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.