Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Database for Contact Form 7, WPforms, Elementor forms — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Database for Contact Form 7, WPforms, Elementor forms, with AI-generated Chinese analysis, references, and POCs.

This page details the vulnerability aggregation profile for Database for Contact Form 7, WPforms, and Elementor forms, categorized under weak cryptographic storage and insecure data handling weaknesses. It compiles a comprehensive record of security issues affecting these popular WordPress form plugins, covering advisory notifications and documented exploits from their initial releases through the present day. The dataset includes flaws ranging from cross-site scripting and SQL injection to unauthorized access and information disclosure, reflecting the evolving threat landscape associated with handling user-submitted data and backend database interactions. By consulting this resource, security professionals and website administrators can effectively track a vendor's security advisory history to understand how quickly known issues are addressed or mitigated. Users can gain a deeper understanding of specific weakness classes commonly exploited in form processing plugins, helping them assess the inherent risks of storing sensitive contact information in plain text or weakly encrypted formats. Additionally, the page allows for a thorough lookup of a product's vulnerability history, enabling teams to identify patterns in past exploits and implement more robust defensive measures. This aggregated view serves as a critical reference for evaluating the long-term security posture of these widely used tools. It facilitates informed decision-making regarding plugin selection, configuration hardening, and ongoing maintenance schedules, ensuring that organizations can maintain a higher standard of data protection without relying solely on isolated incident reports.

Vendor: CRM Perks

CVE ID Title CVSS Severity Published
CVE-2026-14872 Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter - - 2026-08-04
CVE-2026-14870 Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id - - 2026-07-28
CVE-2026-12081 Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field - - 2026-07-13
CVE-2026-9145 Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' CWE-22 6.5 Medium 2026-07-02
CVE-2026-9843 Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value CWE-22 8.1 High 2026-06-20
CVE-2026-3831 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode CWE-862 4.3 Medium 2026-04-01
CVE-2026-2599 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv' CWE-502 9.8 Critical 2026-03-05
CVE-2026-0825 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export CWE-862 5.3 Medium 2026-01-28
CVE-2025-7384 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion CWE-502 9.8 Critical 2025-08-13
CVE-2024-3715 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2024-05-02
CVE-2024-2030 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 6.4 Medium 2024-03-13
CVE-2024-1069 Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload CWE-434 7.2 High 2024-01-31
CVE-2023-31212 WordPress Contact Form Entries Plugin <= 1.3.0 is vulnerable to SQL Injection CWE-89 8.5 High 2023-10-31

All 13 known CVE vulnerabilities affecting Database for Contact Form 7, WPforms, Elementor forms with full Chinese analysis, references, and POCs where available.