Advanced Contact form 7 DB <= 2.0.9 - Missing Authorization
medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1.0
- Disclosed:
- Jun 30, 2026
CVE-2026-57669 on NVD →
Advanced CF7 DB <= 2.0.9 - Cross-Site Request Forgery to Form Entry Deletion
medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via...
- CVSS:
- 5.4
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 8, 2026
CVE-2026-0811 on NVD →
Advanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export
medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export...
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 8, 2026
CVE-2026-0814 on NVD →
Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel)
low
Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.
- CVSS:
- 3.7
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 7, 2025
CVE-2014-2054 on NVD →
PHPSpreadsheet Library < 2.3.0 - XXE Injection
high
The security scanner that prevents XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files, and sensitive information can be disclosed by providing a crafted sheet.
- CVSS:
- 7.5
- Affected:
- up to 2.0.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 7, 2024
CVE-2024-45293 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.3
unknown
[en] The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a...
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 11, 2024
CVE-2024-3723 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.3
unknown
[en] The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 11, 2024
CVE-2024-4319 on NVD →
Advanced Contact form 7 DB <= 2.0.2 - Missing Authorization to Unauthenticated Information Disclosure
medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for submitted forms.
- CVSS:
- 5.3
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 10, 2024
CVE-2024-4319 on NVD →
Advanced Contact form 7 DB <= 2.0.2 - Sensitive Information Exposure
medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form...
- CVSS:
- 5.3
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 10, 2024
CVE-2024-3723 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 1.8.8
unknown
[en] Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- May 25, 2022
CVE-2022-29408 on NVD →
Advanced Contact form 7 DB <= 1.8.7 - Stored Cross-Site Scripting
medium
Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.
- CVSS:
- 6.1
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Apr 21, 2022
CVE-2022-29408 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 1.8.7
unknown
[en] The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.ph...
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.7
- Disclosed:
- Mar 21, 2022
CVE-2021-24905 on NVD →
Advanced Contact form 7 DB <= 1.8.6 - Authenticated Arbitrary File Deletion
high
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php all...
- CVSS:
- 8.8
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.7
- Disclosed:
- Feb 22, 2022
CVE-2021-24905 on NVD →
Advanced Contact Form 7 DB <= 1.6.2 - SQL Injection
critical
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. 1.7.0 contained an additional security patch.
- CVSS:
- 9.8
- Affected:
- up to 1.6.2
- Fixed in:
- 1.7.0
- Disclosed:
- Sep 22, 2020
CVE-2019-13571 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 1.7.1
unknown
[en] A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Jul 29, 2019
CVE-2019-13571 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Sucuri in WordPress Advanced Contact form 7 DB plugin (versions <= 1.6.0).
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 12, 2019
Advanced Contact form 7 DB <= 1.6.0 - SQL Injection
high
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in versions before 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append a...
- CVSS:
- 8.5
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 11, 2019
Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1
unknown
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in versions before 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append a...
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 11, 2019
Advanced Contact form 7 DB [advanced-cf7-db] < 1.1.1
unknown
An authenticated Information Disclosure Vulnerability was found in WordPress Advanced Contact form 7 DB Plugin 1.10 version. In the file /admin/class-advanced-cf7-db-admin.php, in the function vsz_cf7_edit_form_ajax() there's no proper check who can view the contact form entry data.
Update the plugin.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Aug 24, 2017
Advanced Contact form 7 DB [advanced-cf7-db] < 2.0.9
unknown
[en] PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Jun 4, 2014
CVE-2014-2054 on NVD →
Advanced Contact form 7 DB [advanced-cf7-db] < 1.6.1
unknown
The Advanced Contact form 7 DB WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database