Known vulnerabilities in the Database for Contact Form 7, WPforms, Elementor forms plugin
8 security advisories have been published for the Database for Contact Form 7, WPforms, Elementor forms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Database for Contact Form 7, WPforms, Elementor forms - SQL Injection (CVE-2026-14872) MEDIUM
- Database for Contact Form 7, WPforms, Elementor forms - PHP Object Injection (CVE-2026-12081) MEDIUM
- Database for Contact Form 7, WPforms, Elementor forms - Security Vulnerability (CVE-2026-9145) MEDIUM
- Database for Contact Form 7, WPforms, Elementor forms - Remote Code Execution (CVE-2026-9843) HIGH
- Database for Contact Form 7, WPforms, Elementor forms - Broken Access Control (CVE-2026-3831) MEDIUM
- Database for Contact Form 7, WPforms, Elementor forms - PHP Object Injection (CVE-2026-2599) CRITICAL
- Database for Contact Form 7, WPforms, Elementor forms - Broken Access Control (CVE-2026-0825) MEDIUM
- Database for Contact Form 7, WPforms, Elementor forms - Cross-Site Scripting (XSS) (CVE-2024-2030) MEDIUM
- Database For Contact Form 7 Wpforms Elementor Forms - Remote Code Execution (CVE-2024-1069) HIGH