plugin

Contact Form Cfdb7 Vulnerabilities

17 known security issues reported for the Contact Form Cfdb7 WordPress plugin. Most recent disclosed Jul 3, 2025.

3 high 4 medium

Running Contact Form Cfdb7 on your site? Check whether your installed version is affected.

Scan your site free

Contact Form 7 Database Addon <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting via tmpD Parameter

medium

The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Jul 3, 2025

CVE-2025-6740 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.7

unknown

[en] The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.6.8 via the cfdb7_before_send_mail function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from fil...

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
May 2, 2024

CVE-2024-3870 on NVD →

Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information Exposure

medium

The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.6.8 via the cfdb7_before_send_mail function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files up...

CVSS:
5.3
Affected:
up to 1.2.6.8
Fixed in:
1.2.7
Disclosed:
Apr 26, 2024

CVE-2024-3870 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.6.5

unknown

[en] The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

Affected:
up to 1.2.6.5
Fixed in:
1.2.6.5
Disclosed:
Nov 21, 2022

CVE-2022-3634 on NVD →

Contact Form 7 Database Addon <= 1.2.6.3 - CSV Injection

high

The Contact Form 7 Database Addon plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.6.3. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable confi...

CVSS:
7.2
Affected:
up to 1.2.6.3
Fixed in:
1.2.6.5
Disclosed:
Oct 27, 2022

CVE-2022-3634 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.6.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).

Affected:
up to 1.2.6.1
Fixed in:
1.2.6.1
Disclosed:
Dec 22, 2021

CVE-2021-36886 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.6.2

unknown

[en] Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).

Affected:
up to 1.2.6.2
Fixed in:
1.2.6.2
Disclosed:
Dec 22, 2021

CVE-2021-36885 on NVD →

Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.9 - Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).

CVSS:
6.5
Affected:
up to 1.2.5.9
Fixed in:
1.2.6.1
Disclosed:
Nov 12, 2021

CVE-2021-36886 on NVD →

Contact Form 7 Database Addon – CFDB7 <= 1.2.6.1 - Unauthenticated Stored Cross-Site Scripting

medium

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).

CVSS:
6.1
Affected:
up to 1.2.6.1
Fixed in:
1.2.6.2
Disclosed:
Nov 12, 2021

CVE-2021-36885 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.5.6

unknown

[en] Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

Affected:
up to 1.2.5.6
Fixed in:
1.2.5.6
Disclosed:
Mar 18, 2021

CVE-2021-24144 on NVD →

Contact Form 7 Database Addon <= 1.2.5.4 - CSV Injection

high

Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

CVSS:
8.8
Affected:
up to 1.2.5.6
Fixed in:
1.2.5.6
Disclosed:
Jan 25, 2021

CVE-2021-24144 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.5.4

unknown

Insufficient Input Sanitization Leading To Authenticated SQL Injection (SQLi) vulnerability found in WordPress Contact Form 7 Database Addon – CFDB7 plugin (versions <= 1.2.5.3).

Affected:
up to 1.2.5.4
Fixed in:
1.2.5.4
Disclosed:
Jan 21, 2021

Contact Form 7 Database Addon <= 1.2.5.3 - SQL Injection

high

The Contact Form 7 Database Addon plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 1.2.5.3, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the form_id parameter. This can be exploit by authenticated attackers to retrieve sensitive info...

CVSS:
8.8
Affected:
up to 1.2.5.4
Fixed in:
1.2.5.4
Disclosed:
Jan 19, 2021

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.5.4

unknown

The Contact Form 7 Database Addon plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 1.2.5.3, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the form_id parameter. This can be exploit by authenticated attackers to retrieve sensitive info...

Affected:
up to 1.2.5.4
Fixed in:
1.2.5.4
Disclosed:
Jan 19, 2021

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.2.5.4

unknown

The plugin did not properly sanitise the form_ids from the contact_form POST array parameter before using them in a SQL statement in the process_bulk_action() function. This could allow high privilege users, such as admin to perform SQL Injection against the DBMS via the bulk actions: delete, read and unread. Note:...

Affected:
up to 1.2.5.4
Fixed in:
1.2.5.4

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] < 1.3.2

unknown
Affected:
up to 1.3.2
Fixed in:
1.3.2

CVE-2025-6740 on NVD →

Contact Form 7 Database Addon &#8211; CFDB7 [contact-form-cfdb7] <= 1.3.2

unknown
Affected:
up to 1.3.2
Fixed in:
1.3.2

CVE-2025-4665 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database