Database for Contact Form 7, WPforms, Elementor forms <= 1.5.4 - Authenticated (Authenticated+) SQL Injection
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...
- CVSS:
- 6.5
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Jul 27, 2026
CVE-2026-14872 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
high
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 7.2
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 10, 2026
CVE-2026-57708 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Reflected Cross-Site Scripting
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 7, 2026
CVE-2026-14870 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy...
- CVSS:
- 6.5
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jul 1, 2026
CVE-2026-9145 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated PHP Object Injection
high
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerabl...
- CVSS:
- 8.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jun 22, 2026
CVE-2026-12081 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value
high
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the se...
- CVSS:
- 8.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jun 19, 2026
CVE-2026-9843 on NVD →
Contact Form Entries - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode vulnerability
medium
Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode vulnerability
- CVSS:
- 4.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Apr 1, 2026
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 4.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Mar 31, 2026
CVE-2026-3831 on NVD →
Contact Form Entries - Unauthenticated PHP Object Injection via 'download_csv' vulnerability
critical
Unauthenticated PHP Object Injection via 'download_csv' vulnerability
- CVSS:
- 9.8
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Mar 6, 2026
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'
critical
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known PO...
- CVSS:
- 9.8
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Mar 4, 2026
CVE-2026-2599 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to download sensitive form submission da...
- CVSS:
- 5.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Jan 27, 2026
CVE-2026-0825 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion
critical
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additi...
- CVSS:
- 9.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Aug 12, 2025
CVE-2025-7384 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.9
unknown
[en] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- May 2, 2024
CVE-2024-3715 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting
high
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.9
- Disclosed:
- Apr 22, 2024
CVE-2024-3715 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.4
unknown
[en] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Mar 13, 2024
CVE-2024-2030 on NVD →
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Mar 6, 2024
CVE-2024-2030 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.3
unknown
[en] The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 31, 2024
CVE-2024-1069 on NVD →
Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload
high
The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on t...
- CVSS:
- 7.2
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 30, 2024
CVE-2024-1069 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.0
unknown
[en] The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 16, 2024
CVE-2022-3604 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 31, 2023
CVE-2023-31212 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.3.1
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- May 28, 2023
CVE-2023-33311 on NVD →
Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode
high
The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attributes in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authent...
- CVSS:
- 8.8
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- May 22, 2023
CVE-2023-31212 on NVD →
Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode
medium
The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcode attributes in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- May 22, 2023
CVE-2023-33311 on NVD →
Contact Form Entries <= 1.2.9 - CSV Injection
high
The Contact Form Entries plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.9 when outputting to a CSV file. This allows low-level attackers to embed untrusted input contact forms that will be present in exported CSV files, which can result in code execution when these files are d...
- CVSS:
- 7.2
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 21, 2022
CVE-2022-3604 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.1.7
unknown
[en] The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 24, 2022
CVE-2021-25080 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4
unknown
[en] The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 24, 2022
CVE-2021-25079 on NVD →
Contact Form Entries <= 1.2.3 - Reflected Cross-Site Scripting
medium
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
- CVSS:
- 6.1
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Nov 14, 2021
CVE-2021-25079 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4
unknown
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities discovered by Ex.Mi (Patchstack) in WordPress Contact Form Entries plugin (versions <= 1.2.3).
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Nov 14, 2021
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by Ex.Mi (Patchstack) in WordPress Contact Form Entries plugin (versions <= 1.2.3).
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Nov 14, 2021
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.4
unknown
Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by Ex.Mi in WordPress Contact Form Entries plugin (versions <= 1.2.3).
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Nov 14, 2021
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
medium
Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- CVSS:
- 6.1
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 26, 2021
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.2
unknown
Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 26, 2021
Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting
medium
The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- CVSS:
- 6.1
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.1
- Disclosed:
- Aug 24, 2021
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.1
unknown
The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Aug 24, 2021
Contact Form Entries <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
- CVSS:
- 7.2
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 5, 2021
CVE-2021-25080 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2025-7384 on NVD →
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.1
unknown
The plugin does not escape some of its filters before outputting them back in the admin dashboard, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] < 1.2.2
unknown
Numerous plugins from the CRM Perks vendor do not escape parameters before outputting them back in attributes in admin pages, leading to a Reflected Cross-Site Scripting issues executed in the context of a logged in administrator.
It first started with an obvious XSS via the vx_debug GET parameter in 7 plugins, and...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2