plugin

Contact Form Entries Vulnerabilities

38 known security issues reported for the Contact Form Entries WordPress plugin. Most recent disclosed Jul 27, 2026.

3 critical 8 high 11 medium

Running Contact Form Entries on your site? Check whether your installed version is affected.

Scan your site free

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.4 - Authenticated (Authenticated+) SQL Injection

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...

CVSS:
6.5
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Jul 27, 2026

CVE-2026-14872 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

high

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
7.2
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Jul 10, 2026

CVE-2026-57708 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Reflected Cross-Site Scripting

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Jul 7, 2026

CVE-2026-14870 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy...

CVSS:
6.5
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jul 1, 2026

CVE-2026-9145 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated PHP Object Injection

high

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerabl...

CVSS:
8.1
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jun 22, 2026

CVE-2026-12081 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value

high

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the se...

CVSS:
8.1
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jun 19, 2026

CVE-2026-9843 on NVD →

Contact Form Entries - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode vulnerability

medium

Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode vulnerability

CVSS:
4.3
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Apr 1, 2026

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level access...

CVSS:
4.3
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Mar 31, 2026

CVE-2026-3831 on NVD →

Contact Form Entries - Unauthenticated PHP Object Injection via 'download_csv' vulnerability

critical

Unauthenticated PHP Object Injection via 'download_csv' vulnerability

CVSS:
9.8
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Mar 6, 2026

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'

critical

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known PO...

CVSS:
9.8
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Mar 4, 2026

CVE-2026-2599 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to download sensitive form submission da...

CVSS:
5.3
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
Jan 27, 2026

CVE-2026-0825 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion

critical

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additi...

CVSS:
9.8
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Aug 12, 2025

CVE-2025-7384 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.9

unknown

[en] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 1.3.9
Fixed in:
1.3.9
Disclosed:
May 2, 2024

CVE-2024-3715 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting

high

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
7.2
Affected:
up to 1.3.8
Fixed in:
1.3.9
Disclosed:
Apr 22, 2024

CVE-2024-3715 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.4

unknown

[en] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Mar 13, 2024

CVE-2024-2030 on NVD →

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 1.3.3
Fixed in:
1.3.4
Disclosed:
Mar 6, 2024

CVE-2024-2030 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.3

unknown

[en] The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jan 31, 2024

CVE-2024-1069 on NVD →

Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload

high

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on t...

CVSS:
7.2
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Jan 30, 2024

CVE-2024-1069 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.0

unknown

[en] The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Jan 16, 2024

CVE-2022-3604 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 31, 2023

CVE-2023-31212 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.1

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
May 28, 2023

CVE-2023-33311 on NVD →

Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode

high

The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attributes in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authent...

CVSS:
8.8
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
May 22, 2023

CVE-2023-31212 on NVD →

Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode

medium

The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcode attributes in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...

CVSS:
6.4
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
May 22, 2023

CVE-2023-33311 on NVD →

Contact Form Entries <= 1.2.9 - CSV Injection

high

The Contact Form Entries plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.9 when outputting to a CSV file. This allows low-level attackers to embed untrusted input contact forms that will be present in exported CSV files, which can result in code execution when these files are d...

CVSS:
7.2
Affected:
up to 1.2.9
Fixed in:
1.3.0
Disclosed:
Oct 21, 2022

CVE-2022-3604 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.1.7

unknown

[en] The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Jan 24, 2022

CVE-2021-25080 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4

unknown

[en] The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jan 24, 2022

CVE-2021-25079 on NVD →

Contact Form Entries <= 1.2.3 - Reflected Cross-Site Scripting

medium

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

CVSS:
6.1
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Nov 14, 2021

CVE-2021-25079 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4

unknown

Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities discovered by Ex.Mi (Patchstack) in WordPress Contact Form Entries plugin (versions <= 1.2.3).

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Nov 14, 2021

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by Ex.Mi (Patchstack) in WordPress Contact Form Entries plugin (versions <= 1.2.3).

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Nov 14, 2021

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4

unknown

Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by Ex.Mi in WordPress Contact Form Entries plugin (versions <= 1.2.3).

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Nov 14, 2021

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

medium

Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Aug 26, 2021

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.2

unknown

Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Aug 26, 2021

Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting

medium

The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

CVSS:
6.1
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Aug 24, 2021

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.1

unknown

The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Aug 24, 2021

Contact Form Entries <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting

high

The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

CVSS:
7.2
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Jan 5, 2021

CVE-2021-25080 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.4.4

unknown
Affected:
up to 1.4.4
Fixed in:
1.4.4

CVE-2025-7384 on NVD →

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.1

unknown

The plugin does not escape some of its filters before outputting them back in the admin dashboard, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.2.1
Fixed in:
1.2.1

Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.2

unknown

Numerous plugins from the CRM Perks vendor do not escape parameters before outputting them back in attributes in admin pages, leading to a Reflected Cross-Site Scripting issues executed in the context of a logged in administrator. It first started with an obvious XSS via the vx_debug GET parameter in 7 plugins, and...

Affected:
up to 1.2.2
Fixed in:
1.2.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database