Extension WordPress
Vulnérabilités Advanced Contact form 7 DB
Cette page rassemble les failles publiées pour Advanced Contact form 7 DB, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Contact form 7 DB
11 fiches
Advanced Contact form 7 DB <= 2.0.9 – Missing Authorization
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with…
*-2.0.9
2.1.0
30/06/2026
Advanced CF7 DB <= 2.0.9 – Cross-Site Request Forgery to Form Entry Deletion
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes…
*-2.0.9
2.1.0
08/04/2026
Advanced CF7 DB <= 2.0.9 – Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible…
*-2.0.9
2.1.0
08/04/2026
Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 – Use of Vulnerable Component (PHPExcel)
Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.
*-2.0.8
2.0.9
07/04/2025
PHPSpreadsheet Library < 2.3.0 – XXE Injection
The security scanner that prevents XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files, and…
*-2.0.5
Non indiqué
07/10/2024
Advanced Contact form 7 DB <= 2.0.2 – Missing Authorization to Unauthenticated Information Disclosure
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for…
*-2.0.2
2.0.3
10/06/2024
Advanced Contact form 7 DB <= 2.0.2 – Sensitive Information Exposure
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data…
*-2.0.2
2.0.3
10/06/2024
Advanced Contact form 7 DB <= 1.8.7 – Stored Cross-Site Scripting
Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin
*-1.8.7
1.8.8
21/04/2022
Advanced Contact form 7 DB <= 1.8.6 – Authenticated Arbitrary File Deletion
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary…
[*, 1.8.7)
1.8.7
22/02/2022
Advanced Contact Form 7 DB <= 1.6.2 – SQL Injection
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. 1.7.0 contained…
*-1.6.2
1.7.0
22/09/2020
Advanced Contact form 7 DB <= 1.6.0 – SQL Injection
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in versions before 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 1.6.1)
1.6.1
11/04/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.