WordPress Contact Form Plugins Reflected XSS via form_id (CVE-2026-14870)
Security Advisory
CVE-2026-14870
High
WordPress
Affected:
- Database for Contact Form 7 < 1.5.3
- WPforms < 1.5.3
- Elementor forms < 1.5.3
- contact-form-entries < 1.5.3
Fixed in:
- 1.5.3
Referenced CVEs:
CVE-2026-14870
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from wpscan.com, cleaned by our LLM pipeline, and translated to English. View original.