plugin

Advanced Cf7 Db Vulnerabilities

21 known security issues reported for the Advanced Cf7 Db WordPress plugin. Most recent disclosed Jun 30, 2026.

1 critical 3 high 6 medium 1 low

Running Advanced Cf7 Db on your site? Check whether your installed version is affected.

Scan your site free

Advanced Contact form 7 DB <= 2.0.9 - Missing Authorization

medium

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Jun 30, 2026

CVE-2026-57669 on NVD →

Advanced CF7 DB <= 2.0.9 - Cross-Site Request Forgery to Form Entry Deletion

medium

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via...

CVSS:
5.4
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Apr 8, 2026

CVE-2026-0811 on NVD →

Advanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export

medium

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export...

CVSS:
4.3
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Apr 8, 2026

CVE-2026-0814 on NVD →

Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel)

low

Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.

CVSS:
3.7
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Apr 7, 2025

CVE-2014-2054 on NVD →

PHPSpreadsheet Library < 2.3.0 - XXE Injection

high

The security scanner that prevents XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files, and sensitive information can be disclosed by providing a crafted sheet.

CVSS:
7.5
Affected:
up to 2.0.5
Fix:
No patched version reported
Disclosed:
Oct 7, 2024

CVE-2024-45293 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.3

unknown

[en] The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a...

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jun 11, 2024

CVE-2024-3723 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.3

unknown

[en] The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jun 11, 2024

CVE-2024-4319 on NVD →

Advanced Contact form 7 DB <= 2.0.2 - Missing Authorization to Unauthenticated Information Disclosure

medium

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.

CVSS:
5.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jun 10, 2024

CVE-2024-4319 on NVD →

Advanced Contact form 7 DB <= 2.0.2 - Sensitive Information Exposure

medium

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form...

CVSS:
5.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jun 10, 2024

CVE-2024-3723 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 1.8.8

unknown

[en] Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
May 25, 2022

CVE-2022-29408 on NVD →

Advanced Contact form 7 DB <= 1.8.7 - Stored Cross-Site Scripting

medium

Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.

CVSS:
6.1
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Apr 21, 2022

CVE-2022-29408 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 1.8.7

unknown

[en] The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.ph...

Affected:
up to 1.8.7
Fixed in:
1.8.7
Disclosed:
Mar 21, 2022

CVE-2021-24905 on NVD →

Advanced Contact form 7 DB <= 1.8.6 - Authenticated Arbitrary File Deletion

high

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php all...

CVSS:
8.8
Affected:
up to 1.8.7
Fixed in:
1.8.7
Disclosed:
Feb 22, 2022

CVE-2021-24905 on NVD →

Advanced Contact Form 7 DB <= 1.6.2 - SQL Injection

critical

A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. 1.7.0 contained an additional security patch.

CVSS:
9.8
Affected:
up to 1.6.2
Fixed in:
1.7.0
Disclosed:
Sep 22, 2020

CVE-2019-13571 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 1.7.1

unknown

[en] A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Jul 29, 2019

CVE-2019-13571 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Sucuri in WordPress Advanced Contact form 7 DB plugin (versions <= 1.6.0).

Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Apr 12, 2019

Advanced Contact form 7 DB <= 1.6.0 - SQL Injection

high

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in versions before 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append a...

CVSS:
8.5
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Apr 11, 2019

Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1

unknown

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in versions before 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append a...

Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Apr 11, 2019

Advanced Contact form 7 DB [advanced-cf7-db] < 1.1.1

unknown

An authenticated Information Disclosure Vulnerability was found in WordPress Advanced Contact form 7 DB Plugin 1.10 version. In the file /admin/class-advanced-cf7-db-admin.php, in the function vsz_cf7_edit_form_ajax() there's no proper check who can view the contact form entry data. Update the plugin.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Aug 24, 2017

Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.9

unknown

[en] PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Jun 4, 2014

CVE-2014-2054 on NVD →

Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1

unknown

The Advanced Contact form 7 DB WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.

Affected:
up to 1.6.1
Fixed in:
1.6.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database